local privilege escalation in SUSE postgresql init script
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 7.3epss 1.0%
from disclosure to weapon165 days
Published on NVDMar 1
1st PoC+165d
exploitation probability
1.0%top 40% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
In short
A timing flaw in the PostgreSQL startup script allows someone with access to the PostgreSQL account to gain root-level permissions. An attacker could exploit this race condition during system startup to escalate their privileges.
Technical detail
A race condition exists in the SUSE PostgreSQL init script (CWE-61) that can be exploited by an attacker with postgresql account access to achieve local privilege escalation to root. The vulnerability occurs during the initialization phase when file permissions or ownership are set, allowing a malicious user to manipulate the process flow and gain elevated privileges before proper access controls are enforced.
Summary generated and translated by AI from the official description.
A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root.
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Affected products
suse · postgresql-initpublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/45184unverifiedcve_referencewww.exploit-db.com/exploits/45184/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.