systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This presents a substantial security risk when running systemctl from Sudo, because less executes as root when the terminal size is too small to show the complete systemctl output.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-03-03T00:00:00

Updated: 2024-08-02T11:53:53.661Z

Reserved: 2023-02-26T00:00:00

Link: CVE-2023-26604

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-03-03T16:15:10.607

Modified: 2023-11-07T04:09:41.293

Link: CVE-2023-26604

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-03-03T00:00:00Z

Links: CVE-2023-26604 - Bugzilla