posted 2017-09-15
The Gentoo sci-mathematics/gimps package before 28.10-r1 allows
local users to gain root privileges by creating a hard link under
/var/lib/gimps, because an unsafe chown
command is executed whenever the service is started.
The full details, exploit, and mitigation are discussed in my article, End root chowning now (make /etc/init.d great again).