Loading HuntDB...

GHSA-qwp6-cgv8-84vv

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mount via rename() which could result in local privilege escalation. Mounting via rename() could potentially lead to a file being placed elsewhereon the filesystem hierarchy (e.g. /etc/cron.d/) if the directory being cleaned up was on the same physical filesystem. Fixed versions include 1.6.13+nmu1+deb9u1 and 1.6.14.

Related CVEs

Key Information

GHSA ID
GHSA-qwp6-cgv8-84vv
Published
May 14, 2022 12:55 AM
Last Modified
May 14, 2022 12:55 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 29, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.