Description
Description

The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories by walking
the tree with FTS and calling `lchown` and `chmod` on each entry's full pathname while running with an
effective uid of 0. Both syscalls re-resolve the path at the time of the call, after FTS has classified the
entry, and the trees being walked are owned and writable by the untrusted topology user.

A tenant running code on a supervisor node could therefore replace an intermediate directory component with
a symbolic link between classification and the privileged operation, redirecting the root-owned `lchown` or
`chmod` at an arbitrary file on the host. The operation is repeatable at will, since crashing a worker
forces a relaunch and blob updates re-run the walk, so a failed attempt costs the attacker nothing.

This crosses the boundary that `supervisor.run.worker.as.user` and container isolation are intended to
enforce. It is the same defect class as the Hadoop container-executor issues from which this code derives.

Mitigation

Upgrade to 3.1.0, where the privileged walk operates on file descriptors it has already stat'd rather than
on pathnames re-resolved at call time.

Users who cannot upgrade immediately should not run untrusted topology code on supervisors configured with
`supervisor.run.worker.as.user`, since the launcher is the boundary being crossed. Note that the launcher
must be rebuilt and reinstalled after upgrading; replacing the Java artifacts alone is not sufficient.

Credit

The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.
Published: 2026-09-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation to Root via a Time‑of‑Check Race
Action: Patch Now
AI Analysis

Impact

The setuid‑root worker‑launcher binary in Apache Storm modifies worker directory ownership and permissions by walking the filesystem with FTS and invoking lchown and chmod on each pathname while running with effective UID 0. The binary resolves the path again at each syscall, creating a time‑of‑check to time‑of‑use race. An attacker who can replace an intermediate directory component with a symbolic link between classification of a file and the privileged operation, causing the subsequent lchown or chmod to operate on an arbitrary host file. This allows the attacker to change ownership or permissions of critical files and ultimately gain root privileges, thereby violating supervisor isolation intended by supervisor.run.worker.as.user.

Affected Systems

The flaw affects the Apache Storm Worker Launcher component in all releases prior to 3.1.0. Systems running older versions of Storm on supervisor nodes where the worker‑launcher binary is setuid‑root are vulnerable. The issue is tied to the privileged walk performed during worker directory creation and updates, so any deployment that does not upgrade to the hardened version is at risk.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.8, indicating high severity. With no protection against the time‑of‑check race, an attacker can repeatedly exercise the flaw by causing a worker crash and. Because the attacker only needs to run untrusted topology code on a supervisor configured for worker‑as‑user, the attack vector is local and achievable from within on existing network access and can be performed entirely from tenant‑provided code. While the EPSS score is less than 1% (approximately 0.00131) and the vulnerability is not listed in CISA's KEV catalog, its nature and high severity make it a significant risk to any cluster that has not yet adopted the 3.1.0 fix.

Generated by OpenCVE AI on September 21, 2026 at 00:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Storm to version 3.1.0 or later, and rebuild and reinstall the worker‑launcher binary, ensuring that the setuid‑root binary is properly installed; rebuilding the binary is required because simply replacing Java artifacts does not fix the issue.
  • If an immediate upgrade is not possible, do not run untrusted topology code on supervisors that are configured with supervisor.run.worker.as.user, as this setting permits the launcher to cross isolation boundaries.
  • If upgrading is not feasible, consider disabling the setuid‑root permission on the worker‑launcher binary or applying a restrictive SELinux/AppArmor policy that limits the binary’s file access to only its intended directories; this mitigates the race condition by preventing the binary from operating on arbitrary files.

Generated by OpenCVE AI on September 21, 2026 at 00:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories by walking the tree with FTS and calling `lchown` and `chmod` on each entry's full pathname while running with an effective uid of 0. Both syscalls re-resolve the path at the time of the call, after FTS has classified the entry, and the trees being walked are owned and writable by the untrusted topology user. A tenant running code on a supervisor node could therefore replace an intermediate directory component with a symbolic link between classification and the privileged operation, redirecting the root-owned `lchown` or `chmod` at an arbitrary file on the host. The operation is repeatable at will, since crashing a worker forces a relaunch and blob updates re-run the walk, so a failed attempt costs the attacker nothing. This crosses the boundary that `supervisor.run.worker.as.user` and container isolation are intended to enforce. It is the same defect class as the Hadoop container-executor issues from which this code derives. Mitigation Upgrade to 3.1.0, where the privileged walk operates on file descriptors it has already stat'd rather than on pathnames re-resolved at call time. Users who cannot upgrade immediately should not run untrusted topology code on supervisors configured with `supervisor.run.worker.as.user`, since the launcher is the boundary being crossed. Note that the launcher must be rebuilt and reinstalled after upgrading; replacing the Java artifacts alone is not sufficient. Credit The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.
Title Apache Storm Worker Launcher: Local Privilege Escalation to Root via a Time-of-Check Race in the Worker Launcher
Weaknesses CWE-367
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-14T20:00:03.659Z

Reserved: 2026-08-29T10:14:24.656Z

Link: CVE-2026-82429

cve-icon Vulnrichment

Updated: 2026-09-14T15:13:44.810Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T15:17:09.807

Modified: 2026-09-14T20:58:48.430

Link: CVE-2026-82429

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:00:08Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition