Linux Kernel SELinux_PTrace Local Denial of Service Vulnerability
BID:17830
Info
Linux Kernel SELinux_PTrace Local Denial of Service Vulnerability
| Bugtraq ID: | 17830 |
| Class: | Design Error |
| CVE: |
CVE-2006-1052 |
| Remote: | No |
| Local: | Yes |
| Published: | May 04 2006 12:00AM |
| Updated: | Dec 18 2006 09:23PM |
| Credit: | Stephen Smalley <[email protected]> discovered this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux AS 4 Redhat Desktop 4.0 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 Linux kernel 2.6.16 13 Linux kernel 2.6.16 .9 Linux kernel 2.6.16 .8 Linux kernel 2.6.16 .7 Linux kernel 2.6.16 .5 Linux kernel 2.6.16 .4 Linux kernel 2.6.16 .3 Linux kernel 2.6.16 .2 Linux kernel 2.6.16 .11 Linux kernel 2.6.16 .1 Linux kernel 2.6.16 -rc1 Linux kernel 2.6.16 Linux kernel 2.6.15 .6 Linux kernel 2.6.15 .4 Linux kernel 2.6.15 .3 Linux kernel 2.6.15 .2 Linux kernel 2.6.15 .1 Linux kernel 2.6.15 -rc6 Linux kernel 2.6.15 -rc5 Linux kernel 2.6.15 -rc4 Linux kernel 2.6.15 -rc3 Linux kernel 2.6.15 -rc2 Linux kernel 2.6.15 -rc1 Linux kernel 2.6.15 Linux kernel 2.6.14 .5 Linux kernel 2.6.14 .4 Linux kernel 2.6.14 .3 Linux kernel 2.6.14 .2 Linux kernel 2.6.14 .1 Linux kernel 2.6.14 -rc4 Linux kernel 2.6.14 -rc3 Linux kernel 2.6.14 -rc2 Linux kernel 2.6.14 -rc1 Linux kernel 2.6.14 Linux kernel 2.6.13 .4 Linux kernel 2.6.13 .3 Linux kernel 2.6.13 .2 Linux kernel 2.6.13 .1 Linux kernel 2.6.13 -rc7 Linux kernel 2.6.13 -rc6 Linux kernel 2.6.13 -rc4 Linux kernel 2.6.13 -rc1 Linux kernel 2.6.13 Linux kernel 2.6.12 .6 Linux kernel 2.6.12 .5 Linux kernel 2.6.12 .4 Linux kernel 2.6.12 .3 Linux kernel 2.6.12 .2 Linux kernel 2.6.12 .1 Linux kernel 2.6.12 -rc5 Linux kernel 2.6.12 -rc4 Linux kernel 2.6.12 -rc1 Linux kernel 2.6.11 .8 Linux kernel 2.6.11 .7 Linux kernel 2.6.11 .6 Linux kernel 2.6.11 .5 Linux kernel 2.6.11 .12 Linux kernel 2.6.11 .11 Linux kernel 2.6.11 -rc4 Linux kernel 2.6.11 -rc3 Linux kernel 2.6.11 -rc2 Linux kernel 2.6.11 Linux kernel 2.6.10 rc2 Linux kernel 2.6.10 Linux kernel 2.6.9 Linux kernel 2.6.8 rc3 Linux kernel 2.6.8 rc2 Linux kernel 2.6.8 rc1 Linux kernel 2.6.8 Linux kernel 2.6.7 rc1 Linux kernel 2.6.7 Linux kernel 2.6.6 rc1 Linux kernel 2.6.6 Linux kernel 2.6.5 Linux kernel 2.6.4 Linux kernel 2.6.3 Linux kernel 2.6.2 Linux kernel 2.6.1 -rc2 Linux kernel 2.6.1 -rc1 Linux kernel 2.6.1 Linux kernel 2.6 .10 Linux kernel 2.6 -test9-CVS Linux kernel 2.6 -test9 Linux kernel 2.6 -test8 Linux kernel 2.6 -test7 Linux kernel 2.6 -test6 Linux kernel 2.6 -test5 Linux kernel 2.6 -test4 Linux kernel 2.6 -test3 Linux kernel 2.6 -test2 Linux kernel 2.6 -test11 Linux kernel 2.6 -test10 Linux kernel 2.6 -test1 Linux kernel 2.6 Linux kernel 2.6.15.5 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Avaya S8710 R2.0.1 Avaya S8710 R2.0.0 Avaya S8710 CM 3.1 Avaya S8700 R2.0.1 Avaya S8700 R2.0.0 Avaya S8700 CM 3.1 Avaya S8500 R2.0.1 Avaya S8500 R2.0.0 Avaya S8500 CM 3.1 Avaya S8500 0 Avaya S8300 R2.0.1 Avaya S8300 R2.0.0 Avaya S8300 CM 3.1 Avaya S8300 0 Avaya Messaging Storage Server MM3.0 Avaya Converged Communications Server 2.0 |
| Not Vulnerable: | |
Discussion
Linux Kernel SELinux_PTrace Local Denial of Service Vulnerability
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error when SELinux is enabled and ptrace is used.
This vulnerability allows local users to panic the kernel, denying further service to legitimate users.
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error when SELinux is enabled and ptrace is used.
This vulnerability allows local users to panic the kernel, denying further service to legitimate users.
Exploit / POC
Linux Kernel SELinux_PTrace Local Denial of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Linux Kernel SELinux_PTrace Local Denial of Service Vulnerability
Solution:
A fix has been committed to the Linux GIT source-control repository. No official Linux kernel releases are currently known to include this fix.
If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Please see the references for more information and vendor advisories.
Linux kernel 2.6.10
Solution:
A fix has been committed to the Linux GIT source-control repository. No official Linux kernel releases are currently known to include this fix.
If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Please see the references for more information and vendor advisories.
Linux kernel 2.6.10
-
Ubuntu ide-modules-2.6.12-10-amd64-generic-di_2.6.12-10.32_amd64.udeb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.12/ide- modules-2.6.12-10-amd64-generic-di_2.6.12-10.32_amd64.udeb
References
Linux Kernel SELinux_PTrace Local Denial of Service Vulnerability
References:
References:
- [PATCH] selinux: tracer SID fix (Linux Kernel)
- [SECURITY] SELinux ptrace bug (CVE-2006-1052) (Stephen Smalley)
- ASA-2006-200 - Updated kernel packages available for Red Hat Enterprise Linux 4 (Avaya)
- kernel.org Homepage. (Linux Kernel)
- RHSA-2006:0575-22 - Updated kernel packages available for Red Hat Enterprise Lin (Red Hat)