A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when including microcode updates. Local attacker can use this to obtain sensitive information from these files, such as encryption keys or credentials.
References
Link Resource
http://seclists.org/oss-sec/2016/q4/352 Exploit Mailing List Third Party Advisory
http://www.securityfocus.com/bid/94128 Third Party Advisory VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8637 Exploit Issue Tracking Third Party Advisory
https://github.com/dracutdevs/dracut/commit/0db98910a11c12a454eac4c8e86dc7a7bbc764a4 Patch Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2018-08-01T13:00:00

Updated: 2018-08-02T09:57:01

Reserved: 2016-10-12T00:00:00


Link: CVE-2016-8637

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2018-08-01T13:29:00.263

Modified: 2023-02-12T23:26:16.407


Link: CVE-2016-8637

JSON object: View

cve-icon Redhat Information

No data.