BREW-GITLINT-CVE-2026-54552 (GHSA-Q38V-WP89-2W55)

Vulnerability from osv_homebrew – Published: 2026-08-13 16:51 – Updated: 2026-09-17 17:31 – Source website
VLAI
Summary
sh _uid does not drop supplementary groups (incomplete privilege drop)
Details

Impact

The _uid option performed an incomplete privilege drop on Linux/Unix-like systems.

When sh was run from a process with elevated privileges, such as root, and a command was launched with _uid=<unprivileged user>, the child process changed its UID and primary GID but did not reset its supplementary groups. As a result, the child process could retain the parent process’s supplementary groups, potentially including privileged groups such as root, docker, disk, shadow, or sudo.

This could allow a subprocess that was expected to run with reduced privileges to access files or resources available to the original process’s supplementary groups. Users are impacted if they rely on _uid as a privilege boundary when launching commands from a privileged parent process.

Patches

Upgrade to version >= 2.2.4

Workarounds

Avoid using _uid when the user represents a less-privileged user.


{
  "affected": [
    {
      "ecosystem_specific": {
        "fix": "bump",
        "range_state": "fixed",
        "resource": "sh",
        "resource_purl": "pkg:pypi/sh@2.3.0",
        "upstream_fixed_in": "2.2.4"
      },
      "package": {
        "ecosystem": "Homebrew",
        "name": "gitlint",
        "purl": "pkg:brew/gitlint"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0.14.0"
            },
            {
              "fixed": "0.19.1_1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "confidence": "high",
    "source": "matched",
    "strategy": "registry",
    "upstream_evidence": [
      {
        "ecosystem": "PyPI",
        "key": "pkg:pypi/sh@2.3.0",
        "name": "sh",
        "resource": "sh",
        "strategy": "registry",
        "subject_version": "2.3.0"
      }
    ]
  },
  "details": "### Impact\nThe `_uid` option performed an incomplete privilege drop on Linux/Unix-like systems.\n\nWhen `sh` was run from a process with elevated privileges, such as root, and a command was launched with `_uid=\u003cunprivileged user\u003e`, the child process changed its UID and primary GID but did not reset its supplementary groups. As a result, the child process could retain the parent process\u2019s supplementary groups, potentially including privileged groups such as root, docker, disk, shadow, or sudo.\n\nThis could allow a subprocess that was expected to run with reduced privileges to access files or resources available to the original process\u2019s supplementary groups. Users are impacted if they rely on `_uid` as a privilege boundary when launching commands from a privileged parent process.\n\n### Patches\nUpgrade to version \u003e= 2.2.4\n\n### Workarounds\nAvoid using `_uid` when the user represents a less-privileged user.",
  "id": "BREW-gitlint-CVE-2026-54552",
  "modified": "2026-09-17T17:31:02Z",
  "published": "2026-08-13T16:51:23Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/amoffat/sh/security/advisories/GHSA-q38v-wp89-2w55"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/amoffat/sh"
    },
    {
      "type": "WEB",
      "url": "https://github.com/amoffat/sh/releases/tag/2.2.4"
    }
  ],
  "schema_version": "1.7.3",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "sh _uid does not drop supplementary groups (incomplete privilege drop)",
  "upstream": [
    "GHSA-q38v-wp89-2w55",
    "CVE-2026-54552",
    "PYSEC-2026-3540"
  ]
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…