kernel: fs/fhandle.c race condition
Published Mar 16, 2015
1.9
LOWCVSS 2.0
EPSS 0.36%
Description
Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read operations on additional memory locations by changing the handle_bytes value of a file handle during the execution of this function.
Affected products
No data.
Configuration 1
- 7.0
Configuration 2
- ≤ 3.18.9
No data.
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Will not fix
Red Hat Enterprise Linux 7
kernel
Will not fix
Red Hat Enterprise MRG 2
kernel
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | kernel | Will not fix | n/a |
| Red Hat Enterprise MRG 2 | kernel | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This problem does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5. This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 6, 7 and Red Hat Enterprise MRG-2 kernels. This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
References (17)
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00023.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=linux-kernel&m=142247707318982&w=2 mailing-listx_refsource_MLIST
- http://www.debian.org/security/2015/dsa-3170 vendor-advisoryx_refsource_DEBIAN
- http://www.openwall.com/lists/oss-security/2015/01/29/12 mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/72357 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-2660-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2661-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2665-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2667-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2015-1420 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1187534 x_refsource_CONFIRMIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2015-1420
- https://www.cve.org/CVERecord?id=CVE-2015-1420
Change history (0)
No recorded changes yet.