Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Fedora 38: FEDORA-2023-d6dbdf62ad Critical: PRRTE Race Condition

fedora
Calendar Grey October 4, 2023
Scroller Fedora
A security patch addressing CVE-2023-41915 has been implemented in the updates for PRRTE in Fedora 38, resolving significant issues related to file ownership vulnerabilities.
Security fix for CVE-2023-41915

Summary

PRRTE is the PMIx Reference Run Time Environment.

The project is formally referred to in documentation by "PRRTE", and

the GitHub repository is "openpmix/prrte".

However, we have found that most users do not like typing the two

consecutive "r"s in the name. Hence, all of the internal API symbols,

environment variables, MCA frameworks, and CLI executables all use the

abbreviated "prte" (one "r", not two) for convenience.

Update Information:

Security fix for CVE-2023-41915

Change Log

* Mon Sep 25 2023 Michel Lind - 2.0.2-5 - Rebuild for pmix 4.1.3 * Fri Jul 21 2023 Fedora Release Engineering - 2.0.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild

References


[ 1 ] Bug #2238898 - CVE-2023-41915 pmix: race condition allows attackers to obtain ownership of arbitrary files https://bugzilla.redhat.com/show_bug.cgi?id=2238898

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-d6dbdf62ad' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: prrte
Product: Fedora 38
Version: 2.0.2
Release: 5.fc38
Summary: PMIx Reference RunTime Environment (PRRTE)

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.