Bug ID 1223510
Summary VUL-0: CVE-2024-33904: hyprland: race condition in temporary file handling leads to code execution
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.6
Hardware Other
URL https://smash.suse.de/issue/403465/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee packaging@sp1rit.anonaddy.me
Reporter smash_bz@suse.de
QA Contact security-team@suse.de
CC carlos.lopez@suse.com
Target Milestone ---
Found By Security Response Team
Blocker ---

In plugins/HookSystem.cpp in Hyprland through 0.39.1 (before 28c8561), through
a race condition, a local attacker can cause execution of arbitrary assembly
code by writing to a predictable temporary file.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-33904
https://www.cve.org/CVERecord?id=CVE-2024-33904
https://github.com/hyprwm/Hyprland/commit/28c85619243e6320e75d7abcfe8244fa99d054dd
https://github.com/hyprwm/Hyprland/issues/5787
http://www.openwall.com/lists/oss-security/2024/04/28/3


You are receiving this mail because: