apport created lock file in wrong directory
Description
Sander Bos discovered Apport's lock file was in a world-writable directory which allowed all users to prevent crash handling.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Sander Bos discovered Apport's lock file resides in a world-writable directory, allowing any local user to prevent crash handling.
Vulnerability
Sander Bos discovered that Apport, the crash-reporting system debugger for Ubuntu, creates a lock file (/var/lock/apport.lock) in a world-writable directory. This allows any local user to manipulate the lock file, preventing the apport service from processing crash dumps and thus blocking crash handling entirely. The vulnerability affects all supported versions of Ubuntu at the time of disclosure; the fixing update was released in USN-4171-1 and USN-4171-2 [1][2].
Exploitation
A local attacker does not require any special privileges, only write access to the world-writable directory containing the lock file. By removing, creating, or holding the lock file, the attacker can prevent apport from acquiring its lock, thereby stopping crash handling for all processes on the system [2]. No user interaction is needed beyond the attacker having local user access.
Impact
Successful exploitation results in a denial of service (DoS) condition: apport will fail to process any crash dumps, including those from privileged processes. The vulnerability does not allow for code execution or privilege escalation, but it can hide evidence of other attacks by suppressing crash reports [1][2].
Mitigation
The vulnerability has been fixed in apport versions shipped with Ubuntu Security Notice USN-4171-1 (for main Ubuntu releases) and USN-4171-2 (for Ubuntu 14.04 ESM), both released in late October/early November 2019 [1][2]. Users should update the apport package to the latest version available in their distribution's repository. No workaround is necessary after applying the update.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 2.14.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- usn.ubuntu.com/usn/usn-4171-1mitrex_refsource_MISC
- usn.ubuntu.com/usn/usn-4171-2mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.