1. Vulnerability Overview
I am requesting a CVE for an OS Command Injection vulnerability (CWE-78) discovered in the iproute2mac project. The flaw allowed an attacker to execute arbitrary system commands by manipulating command-line arguments passed to the ip link show functionality.
2. Technical Details
- Component:
ip command handler (iproute2mac.py)
- Root Cause: User-controlled input from
sys.argv was concatenated directly into a string passed to subprocess.getstatusoutput(). Because this function inherently spawns a shell (shell=True), an attacker could break out of the intended command context using shell metacharacters (e.g., ;, &&).
- Attack Vector: Local execution (e.g.,
ip link show "eth0; id")
3. Impact
While this is a local CLI tool, arbitrary command injection via argument manipulation is a severe security boundary violation. If this tool is invoked by a secondary application or script processing untrusted input, it leads directly to Remote Code Execution (RCE).
4. Resolution
- The maintainer acknowledged the report promptly and pushed a fix in commit
d31140b.
- The fix migrated the unsafe
subprocess.getstatusoutput() to subprocess.run() with argument arrays, eliminating the shell injection vector.
- The patch was officially released in
v1.7.5.
5. CVE Request Justification
I am submitting this request independently, with the awareness of the maintainer's patch. Assigning a CVE provides a standardized identifier for downstream consumers to track this security fix in their dependency management and vulnerability scanners.
6. References
1. Vulnerability Overview
I am requesting a CVE for an OS Command Injection vulnerability (CWE-78) discovered in the
iproute2macproject. The flaw allowed an attacker to execute arbitrary system commands by manipulating command-line arguments passed to theip link showfunctionality.2. Technical Details
ipcommand handler (iproute2mac.py)sys.argvwas concatenated directly into a string passed tosubprocess.getstatusoutput(). Because this function inherently spawns a shell (shell=True), an attacker could break out of the intended command context using shell metacharacters (e.g.,;,&&).ip link show "eth0; id")3. Impact
While this is a local CLI tool, arbitrary command injection via argument manipulation is a severe security boundary violation. If this tool is invoked by a secondary application or script processing untrusted input, it leads directly to Remote Code Execution (RCE).
4. Resolution
d31140b.subprocess.getstatusoutput()tosubprocess.run()with argument arrays, eliminating the shell injection vector.v1.7.5.5. CVE Request Justification
I am submitting this request independently, with the awareness of the maintainer's patch. Assigning a CVE provides a standardized identifier for downstream consumers to track this security fix in their dependency management and vulnerability scanners.
6. References