kernel: offset2lib patch protection bypass
Published Jun 19, 2017
7.8
HIGHCVSS 3.1
EPSS 2.25%
Description
The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed with 1GB of arguments or environmental strings then the stack occupies the address 0x80000000 and the PIE binary is mapped above 0x40000000 nullifying the protection of the offset2lib patch. This affects Linux Kernel version 4.11.5 and earlier. This is a different issue than CVE-2017-1000371. This issue appears to be limited to i386 based systems.
Affected products
No data.
- ≥ 4.1 · < 4.1.43
- ≥ 4.2 · < 4.4.78
- ≥ 4.5 · < 4.9.39
- ≥ 4.10 · < 4.11.12
- ≥ 4.12 · < 4.12.3
No data.
Red Hat Enterprise Linux 5
kernel
Will not fix
Red Hat Enterprise Linux 6
kernel
Will not fix
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise MRG 2
realtime-kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise MRG 2 | realtime-kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 7 and MRG-2 as the i686 architecture is not supported by this kernel. This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5 and 6. At this time there is no plan to release an update to fix this issue.
References (9)
- http://www.debian.org/security/2017/dsa-3981 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.securityfocus.com/bid/99149 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2017-1000370 x_refsource_CONFIRMThird Party AdvisoryVDB EntryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1462153 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000370
- https://www.cve.org/CVERecord?id=CVE-2017-1000370
- https://www.exploit-db.com/exploits/42273/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/42274/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.debian.org/security/2017/dsa-3981 | vendor-advisoryx_refsource_DEBIANThird Party Advisory | |
| http://www.securityfocus.com/bid/99149 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2017-1000370 | x_refsource_CONFIRMThird Party AdvisoryVDB EntryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1462153 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-1000370 | ||
| https://www.cve.org/CVERecord?id=CVE-2017-1000370 | ||
| https://www.exploit-db.com/exploits/42273/ | exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry | |
| https://www.exploit-db.com/exploits/42274/ | exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry | |
| https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.