A Critical Vulnerability in Red Hat Insights-Client Affects Northeast India
A recently disclosed vulnerability, CVE-2023-3972, has been found in the Red Hat Insights-Client software. This security flaw, if exploited, could potentially impact systems in Northeast India and beyond, as it allows for local privilege escalation.
Vulnerability Details
The vulnerability arises due to insecure file operations or unsafe handling of temporary files and directories in the Insights-Client software. Before the Insights-Client is registered on a system by the root user, an unprivileged local user or attacker can create a directory (/var/tmp/insights-client) with read, write, and execute permissions.
After the Insights-Client is registered by the root user, the attacker can control the directory content that the Insights are using by placing malicious scripts into it and executing arbitrary code as root, bypassing SELinux protections.
CVSS Scores and Vector Strings
The Common Vulnerability Scoring System (CVSS) provides a standard for assessing the severity of cybersecurity vulnerabilities. The CVSS scores for CVE-2023-3972 are as follows:
- CVSS v4.0: Base Score: 7.8 (High)
- CVSS v3.x: Base Score: 7.8 (High)
- CVSS v2.0: Base Score: Not yet provided
Impact on Northeast India and Broader Indian Context
Given the widespread use of Red Hat Enterprise Linux in India, including in Northeast India, organizations running this operating system should be aware of this vulnerability and take appropriate measures to protect their systems.
Affected Software Configurations
The vulnerability affects versions of Red Hat Insights-Client up to 3.2.2. It also affects various configurations of Red Hat Enterprise Linux, including versions 7.0, 8.0, 9.0, and their respective Enterprise Linux for ARM 64, Enterprise Linux for IBM Z Systems, Enterprise Linux for Power Little Endian, and Enterprise Linux for Power Big Endian.
Mitigation and Solutions
Red Hat has issued several advisories (RHSA-2023:6264, RHSA-2023:6282, RHSA-2023:6283, RHSA-2023:6284, RHSA-2023:6795, RHSA-2023:6796, RHSA-2023:6798, RHSA-2023:6811) and a patch (CVE-2023-3972) to address this vulnerability. Users are advised to apply these updates as soon as possible.
Reflections and Future Considerations
The discovery and disclosure of this vulnerability serve as a reminder of the importance of maintaining up-to-date software and applying security patches promptly. As cyber threats continue to evolve, it is crucial for organizations to prioritize cybersecurity and invest in proactive measures to protect their digital assets.