CVE-2022-21944 HIGH

CVE-2022-21944: watchman: chown in watchman@.socket unit allows symlink attack

Vendor Opensuse
Product openSUSE Backports SLE-15-SP3
Weakness CWE-59
Published January 26, 2022
Last update September 16, 2024

CVSS base score

7.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

A UNIX Symbolic Link (Symlink) Following vulnerability in the systemd service file for watchman of openSUSE Backports SLE-15-SP3, Factory allows local attackers to escalate to root. This issue affects: openSUSE Backports SLE-15-SP3 watchman versions prior to 4.9.0. openSUSE Factory watchman versions prior to 4.9.0-9.1.

Key dates

02Disclosure timeline

January 26, 2022 CVE published
September 16, 2024 Record updated