VDB
Sign up
HIGH7.8

GHSA-9mc5-7qhg-fp3w

Below has Incorrect Permission Assignment for Critical Resource

Details

### Impact A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed local unprivileged users to escalate to root privileges through symlink attacks that manipulate files such as /etc/shadow.

### Patches https://github.com/facebookincubator/below/commit/10e73a21d67baa2cd613ee92ce999cda145e1a83

This is included in version 0.9.0

### Workarounds Change the permission on `/var/log/below` manually

### References https://www.facebook.com/security/advisories/cve-2025-27591 https://www.cve.org/CVERecord?id=CVE-2025-27591

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/below
Introduced in: 0Fixed in: 0.9.0

Upgrade below to 0.9.0 or newer (ecosystem crates.io).

References