We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-6760

ktrace(2) fails to detach when executing a setuid binary



Assignerfreebsd
Reserved2024-07-15
Published2024-08-11
Updated2024-10-29

Description

A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivileged users to trace and inspect the behavior of setuid programs. The bug may be used by an unprivileged user to read the contents of files to which they would not otherwise have access, such as the local password database.

Product status

Default status
unknown

14.1-RELEASE before p3
affected

14.0-RELEASE before p9
affected

13.3-RELEASE before p5
affected

References

https://security.freebsd.org/advisories/FreeBSD-SA-24:06.ktrace.asc vendor-advisory

cve.org CVE-2024-6760

nvd.nist.gov CVE-2024-6760

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-6760
Support options

Helpdesk Telegram

Subscribe to our newsletter to learn more about our work.