Root Privileges Vulnerability in Linux sccache

CVE-2023-1521

Currently unrated 🤨

Key Information

Vendor
Mozilla
Status
Sccache
Vendor
CVE Published:
26 November 2024

Summary

On Linux the sccache client can execute arbitrary code with the privileges of a local sccache server, by preloading the code in a shared library passed to LD_PRELOAD.

If the server is run as root (which is the default when installing the snap package https://snapcraft.io/sccache ), this means a user running the sccache client can get root privileges.

Affected Version(s)

sccache < 0.4.0

Refferences

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

Paolo Tranquilli (@redsun82)
.