CVE-2016-10156

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
23/01/2017
Last modified:
20/04/2025

Description

A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features, allowing local attackers to escalate their privileges to root. This is fixed in v229.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:systemd_project:systemd:228:*:*:*:*:*:*:*