Executive brief
Pardus Boot Repair is a system utility used to diagnose and fix boot issues on Pardus Linux systems. An OS command injection vulnerability allows an attacker to execute arbitrary system commands with elevated privileges, potentially compromising system integrity and enabling complete system takeover.
Technical details
The vulnerability is an OS command injection (CWE-78) in TÜBİTAK BİLGEM Pardus Boot Repair that stems from improper neutralization of special elements in shell commands. The application fails to properly sanitize user input before passing it to OS command execution functions, allowing attackers to inject arbitrary commands. Exploitation requires local access and user interaction (running the application). A successful exploit enables arbitrary command execution with the privileges of the Boot Repair process. The vulnerability affects versions 1.0.7 and earlier; version 1.0.8 or later contains the fix.
Affected products
- TÜBİTAK BİLGEM Pardus Boot Repair 1.0.7 and earlier
Timeline
- 2026-08-31: disclosed