Back

LOW

kernel: proc: protect mm start_code/end_code in /proc/pid/stat

Published Jul 18, 2011

Description

The do_task_stat function in fs/proc/array.c in the Linux kernel before 2.6.39-rc1 does not perform an expected uid check, which makes it easier for local users to defeat the ASLR protection mechanism by reading the start_code and end_code fields in the /proc/#####/stat file for a process executing a PIE binary.

Affected products

Remediation

Red Hat statement

Red Hat Enterprise Linux 4 is now in Production 3 of the maintenance life-cycle, https://access.redhat.com/support/policy/updates/errata/, therefore the fix for this issue is not currently planned to be included in the future updates. Future kernel updates in Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG may address this flaw.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner canonical
Published Jul 18, 2011
Updated Aug 6, 2024
Reserved Feb 1, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Mar 11, 2011