Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 841890 (CVE-2021-3982) - <x11-wm/mutter-42.0: niceness setting privilege escalation
Summary: <x11-wm/mutter-42.0: niceness setting privilege escalation
Status: RESOLVED FIXED
Alias: CVE-2021-3982
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://gitlab.gnome.org/GNOME/gnome-...
Whiteboard: B3 [noglsa]
Keywords:
Depends on: gnome-42-stable
Blocks:
  Show dependency tree
 
Reported: 2022-04-30 22:46 UTC by John Helmert III
Modified: 2023-01-06 17:18 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-04-30 22:46:42 UTC
CVE-2021-3982 (https://bugzilla.redhat.com/show_bug.cgi?id=2024174):

Linux distributions using CAP_SYS_NICE for gnome-shell may be exposed to a privilege escalation issue. An attacker, with low privilege permissions, may take advantage of the way CAP_SYS_NICE is currently implemented and eventually load code to increase its process scheduler priority leading to possible DoS of other services running in the same machine.

The issue was reported in gnome-shell, but apparently fixed in mutter:

https://gitlab.gnome.org/GNOME/mutter/-/merge_requests/2060
https://gitlab.gnome.org/GNOME/mutter/-/commit/820aa18126674dcee73f47afb23ed89b57251e2d
Comment 1 Matt Turner gentoo-dev 2022-05-03 01:46:07 UTC
I don't think we're affected because we don't set any caps on gnome-shell?

There's a github pull request to do so, but I never merged it: https://github.com/gentoo/gentoo/pull/21669

Someone confirm that we're not affected?

In any case, the commit in mutter is included in 42.0.
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-01-06 17:18:10 UTC
Impact is low, exploitation is likely going to be complex, and it's unclear whether we're actually affected anyway. No GLSA.