MEDIUM 5.5 Microsoft

CVE-2022-0563

A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.

Microsoft Security Update 2022-Feb: A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.

Affected Products

References

Published: 2022-02-08 · Source: Microsoft · Feed updated: 2026-09-07
This medium severity vulnerability with a CVSS score of 5.5 was published on 2022-02-08 via Microsoft. Affected: cm1 util-linux 2.32.1-7 on CBL Mariner 1.0, cbl2 util-linux 2.37.4-1 on CBL Mariner 2.0.
vulnfeed aggregates 10539 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.