ALAS2-2022-1878

Related Vulnerabilities: CVE-2018-7738  

A command injection flaw was found in the way util-linux implements umount autocompletion in Bash. An attacker with the ability to mount a filesystem with custom mount points may execute arbitrary commands on behalf of the user who triggers the umount autocompletion. (CVE-2018-7738)

ALAS2-2022-1878


Amazon Linux 2 Security Advisory: ALAS-2022-1878
Advisory Release Date: 2022-11-15 18:43 Pacific
Advisory Updated Date: 2022-12-06 22:42 Pacific
Severity: Medium
References: CVE-2018-7738 

Issue Overview:

A command injection flaw was found in the way util-linux implements umount autocompletion in Bash. An attacker with the ability to mount a filesystem with custom mount points may execute arbitrary commands on behalf of the user who triggers the umount autocompletion. (CVE-2018-7738)


Affected Packages:

util-linux


Issue Correction:
Run yum update util-linux to update your system.

New Packages:
aarch64:
    util-linux-2.30.2-2.amzn2.0.9.aarch64
    libfdisk-2.30.2-2.amzn2.0.9.aarch64
    libfdisk-devel-2.30.2-2.amzn2.0.9.aarch64
    libsmartcols-2.30.2-2.amzn2.0.9.aarch64
    libsmartcols-devel-2.30.2-2.amzn2.0.9.aarch64
    libmount-2.30.2-2.amzn2.0.9.aarch64
    libmount-devel-2.30.2-2.amzn2.0.9.aarch64
    libblkid-2.30.2-2.amzn2.0.9.aarch64
    libblkid-devel-2.30.2-2.amzn2.0.9.aarch64
    libuuid-2.30.2-2.amzn2.0.9.aarch64
    libuuid-devel-2.30.2-2.amzn2.0.9.aarch64
    uuidd-2.30.2-2.amzn2.0.9.aarch64
    python-libmount-2.30.2-2.amzn2.0.9.aarch64
    util-linux-user-2.30.2-2.amzn2.0.9.aarch64
    util-linux-debuginfo-2.30.2-2.amzn2.0.9.aarch64

i686:
    util-linux-2.30.2-2.amzn2.0.9.i686
    libfdisk-2.30.2-2.amzn2.0.9.i686
    libfdisk-devel-2.30.2-2.amzn2.0.9.i686
    libsmartcols-2.30.2-2.amzn2.0.9.i686
    libsmartcols-devel-2.30.2-2.amzn2.0.9.i686
    libmount-2.30.2-2.amzn2.0.9.i686
    libmount-devel-2.30.2-2.amzn2.0.9.i686
    libblkid-2.30.2-2.amzn2.0.9.i686
    libblkid-devel-2.30.2-2.amzn2.0.9.i686
    libuuid-2.30.2-2.amzn2.0.9.i686
    libuuid-devel-2.30.2-2.amzn2.0.9.i686
    uuidd-2.30.2-2.amzn2.0.9.i686
    python-libmount-2.30.2-2.amzn2.0.9.i686
    util-linux-user-2.30.2-2.amzn2.0.9.i686
    util-linux-debuginfo-2.30.2-2.amzn2.0.9.i686

src:
    util-linux-2.30.2-2.amzn2.0.9.src

x86_64:
    util-linux-2.30.2-2.amzn2.0.9.x86_64
    libfdisk-2.30.2-2.amzn2.0.9.x86_64
    libfdisk-devel-2.30.2-2.amzn2.0.9.x86_64
    libsmartcols-2.30.2-2.amzn2.0.9.x86_64
    libsmartcols-devel-2.30.2-2.amzn2.0.9.x86_64
    libmount-2.30.2-2.amzn2.0.9.x86_64
    libmount-devel-2.30.2-2.amzn2.0.9.x86_64
    libblkid-2.30.2-2.amzn2.0.9.x86_64
    libblkid-devel-2.30.2-2.amzn2.0.9.x86_64
    libuuid-2.30.2-2.amzn2.0.9.x86_64
    libuuid-devel-2.30.2-2.amzn2.0.9.x86_64
    uuidd-2.30.2-2.amzn2.0.9.x86_64
    python-libmount-2.30.2-2.amzn2.0.9.x86_64
    util-linux-user-2.30.2-2.amzn2.0.9.x86_64
    util-linux-debuginfo-2.30.2-2.amzn2.0.9.x86_64