Executive brief
Apache Storm is a distributed real-time data processing system. The setuid-root worker-launcher binary contains a time-of-check-time-of-use (TOCTOU) vulnerability that allows an untrusted tenant running code on a supervisor node to redirect privileged file operations to arbitrary locations on the host. An attacker could exploit this to escalate privileges and compromise the integrity of the host system.
Technical details
The vulnerability is a TOCTOU symlink-attack in the setuid-root worker-launcher binary. The flaw exists in how the launcher walks worker directory trees using FTS (File Tree Traverse) and then performs lchown and chmod operations on each entry using full pathnames while running as root (uid 0). Because the paths are re-resolved at syscall time after FTS has classified them, an unprivileged tenant can replace an intermediate directory component with a symbolic link between classification and the privileged operation, redirecting root-owned operations to arbitrary files. The attack requires code execution on a supervisor node and is repeatable—failed attempts cost nothing since worker crashes trigger re-launches. The fix (version 3.1.0) operates on pre-stat'd file descriptors instead of re-resolving pathnames. The launcher binary must be rebuilt and reinstalled; upgrading Java artifacts alone is insufficient.
Affected products
- Apache Storm before 3.1.0
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Fix available in version 3.1.0