Setroubleshoot Project maintains a niche diagnostic and troubleshooting utility for Linux SELinux policy enforcement, where the durable vulnerability signal centers on command-injection weaknesses arising from its role processing and interpreting system alerts. The product's exposure to untrusted policy and log input creates a structural injection surface that defenders should monitor when the utility runs with elevated privilege. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Setroubleshoot Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-4989HIGH setroubleshoot allows local users to bypass an intended container protection mechanism and execute arbitrary commands by (1) triggering an SELinux denial with a crafted file name, | Apr 11, 2017 | 7.0 | 23 | NO | NO |
CVE-2016-4446HIGH The allow_execstack plugin for setroubleshoot allows local users to execute arbitrary commands by triggering an execstack SELinux denial with a crafted filename, related to the com | Apr 11, 2017 | 7.0 | 23 | NO | NO |
CVE-2016-4445HIGH The fix_lookup_id function in sealert in setroubleshoot before 3.2.23 allows local users to execute arbitrary commands as root by triggering an SELinux denial with a crafted file n | Apr 11, 2017 | 7.0 | 22 | NO | NO |
CVE-2016-4444HIGH The allow_execmod plugin for setroubleshoot before 3.2.23 allows local users to execute arbitrary commands by triggering an execmod SELinux denial with a crafted binary filename, r | Apr 11, 2017 | 7.0 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Setroubleshoot Project.
Media articles that mention a CVE ID that affects a product developed by Setroubleshoot Project — matched by CVE ID, not by vendor name.