about CVE-2020-14367

chengyechun <[email protected]>
Newsgroups gmane.comp.time.chrony.user
Message-ID <[email protected]>
All,

I'm using chrony version 4.1 on an embedded Linux system and I found something about CVE-2020-14367:if some user with privileged to change the chronyd.pid file, like echo another pid > chronyd.pid, and then we cann’t use the command “chronyd” to start chronyd service; This is because the checkpid function checks whether a valid pid exists in the pid file. However, if the pid value in the chrony.pid file is not that of the chronyd service, the denial of service will occur. Check whether the PID in the chronyd.pid file is the PID of the chronyd service instead of rejecting the file?

Thank you for any reply
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.