chrony: Symlink vulnerability A vulnerability in chrony may allow a privileged attacker to cause data loss via a symlink. chrony 2020-08-30 2020-08-30 738154 local 3.5.1 3.5.1

chrony is a versatile implementation of the Network Time Protocol (NTP).

It was found that chrony did not check whether its PID file was a symlink.

A local attacker could perform symlink attack(s) to overwrite arbitrary files with root privileges.

There is no known workaround at this time.

All chrony users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-misc/chrony-3.5.1"
CVE-2020-14367 chrony-3.5.1 release announcement sam_c sam_c