CVE-2022-29800

Publication date 27 April 2022

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

4.7 · Medium

Score breakdown

A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists because there is a certain time between the scripts being discovered and them being run. An attacker can abuse this vulnerability to replace scripts that networkd-dispatcher believes to be owned by root with ones that are not.

Status

Package Ubuntu Release Status
networkd-dispatcher 22.04 LTS jammy
Fixed 2.1-2ubuntu0.22.04.1
21.10 impish
Fixed 2.1-2ubuntu0.21.10.1
20.04 LTS focal
Fixed 2.1-2~ubuntu20.04.2
18.04 LTS bionic
Fixed 1.7-0ubuntu3.4

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
networkd-dispatcher

Severity score breakdown

Parameter Value
Base score 4.7 · Medium
Attack vector Local
Attack complexity High
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact High
Availability impact None
Vector CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N