kernel: x86-64: seccomp: 32/64 syscall hole
Published Mar 6, 2009
3.6
LOWCVSS 2.0
EPSS 0.93%
Description
The __secure_computing function in kernel/seccomp.c in the seccomp subsystem in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform, when CONFIG_SECCOMP is enabled, does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass intended access restrictions via crafted syscalls that are misinterpreted as (a) stat or (b) chmod, a related issue to CVE-2009-0342 and CVE-2009-0343.
Affected products
No data.
- 2.6.25
- 2.6.25.1
- 2.6.25.2
- 2.6.25.3
- 2.6.25.4
- 2.6.25.5
- 2.6.25.6
- 2.6.25.7
- 2.6.25.8
- 2.6.25.9
- 2.6.25.10
- 2.6.25.11
- 2.6.25.12
No data.
MRG for RHEL-5
kernel-rt-0:2.6.24.7-111.el5rt
Fixed · RHSA-2009:0451
| Product | Package | State | Advisory |
|---|---|---|---|
| MRG for RHEL-5 | kernel-rt-0:2.6.24.7-111.el5rt | Fixed | RHSA-2009:0451 |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 3, 4, and 5.
References (27)
- http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00007.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html vendor-advisoryx_refsource_SUSE
- http://lkml.org/lkml/2009/2/28/23 mailing-listx_refsource_MLIST
- http://marc.info/?l=linux-kernel&m=123579056530191&w=2 mailing-listx_refsource_MLIST
- http://marc.info/?l=linux-kernel&m=123579069630311&w=2 mailing-listx_refsource_MLISTExploit
- http://marc.info/?l=oss-security&m=123597627132485&w=2 mailing-listx_refsource_MLIST
- http://scary.beasts.org/security/CESA-2009-001.html x_refsource_MISCExploit
- http://scary.beasts.org/security/CESA-2009-004.html x_refsource_MISC
- http://scarybeastsecurity.blogspot.com/2009/02/linux-kernel-minor-seccomp.html x_refsource_MISC
- http://secunia.com/advisories/34084 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/34786 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/34917 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35121 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35185 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35390 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35394 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.debian.org/security/2009/dsa-1800 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:118 vendor-advisoryx_refsource_MANDRIVA
- http://www.redhat.com/support/errata/RHSA-2009-0451.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/33948 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/usn-751-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2009-0835 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=487255 x_refsource_MISCExploitIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2009-0835
- https://www.cve.org/CVERecord?id=CVE-2009-0835
Change history (0)
No recorded changes yet.