Impact
An integer overflow occurs in the offset calculation performed by the do_lastlog() function when Cockpit is executed on ILP32 (32‑bit integer, long, pointer) builds. The flaw allows a low‑privileged authenticated user who has been granted a specially large User ID to cause the calculated offset to wrap around. The victim can then read from and overwrite other users' lastlog records, potentially exposing or altering sensitive login accounting information. No exploitation of system privilege escalation or remote code execution is indicated by the supplied data.
Affected Systems
The vulnerability affects Red Hat Enterprise Linux 7, 8, 9, and 10, as well as Red Hat OpenShift Dev Spaces 3. Exact version numbers are not listed in the CNA data; the build type (ILP32) is the determining factor for whether the impact applies.
Risk and Exploitability
The CVSS score of 3.6 indicates a moderate level of risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests it is not widely exploited as of the latest data. Attackers need a locally authenticated account and the ability to assign large UIDs to invoke the overflow, so the vector is largely limited to local, enterprise environments that use 32‑bit builds of Cockpit. The primary threat is the unauthorized disclosure or modification of lastlog entries rather than escalated privileges or remote compromise.
OpenCVE Enrichment