CVE-2022-0563 is a medium-severity flaw in util-linux chfn and chsh utilities, specifically when compiled with Readline support, affecting versions prior to 2.37.4, as well as NetApp products utilizing util-linux. This vulnerability allows an unprivileged local user to read root-owned files due to the Readline library's handling of the INPUTRC environment variable, potentially leading to privilege escalation. The attack requires local access and has low complexity, with a CVSS score of 5.5. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.37.4CPE matchmatch criteria | cpe:2.3:a:kernel:util-linux:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2022-0563
Mar 8, 2022util-linux: partial disclosure of arbitrary files in chfn and chsh when compiled with libreadline
Feb 14, 2022A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.
Feb 8, 2022