Linux Kernel Prior to 2.6.24.1 'vmsplice_to_user()' Local Privilege Escalation Vulnerability
BID:27799
Info
Linux Kernel Prior to 2.6.24.1 'vmsplice_to_user()' Local Privilege Escalation Vulnerability
| Bugtraq ID: | 27799 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-0009 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 08 2008 12:00AM |
| Updated: | May 07 2015 05:14PM |
| Credit: | Wojciech Purczynskiof iSEC Security Research and qaaz are credited with the discovery of this issue. |
| Vulnerable: |
Turbolinux Turbolinux Server 11 x64 Turbolinux Turbolinux Server 11 Red Hat Fedora 7 Linux kernel 2.6.24 -rc5 Linux kernel 2.6.24 -rc4 Linux kernel 2.6.24 -rc3 Linux kernel 2.6.23 .7 Linux kernel 2.6.23 .6 Linux kernel 2.6.23 .5 Linux kernel 2.6.23 .4 Linux kernel 2.6.23 .3 Linux kernel 2.6.23 .2 Linux kernel 2.6.23 -rc2 Linux kernel 2.6.23 -rc1 Linux kernel 2.6.23 Linux kernel 2.6.24-rc2 Linux kernel 2.6.24-rc1 Linux kernel 2.6.23.14 Linux kernel 2.6.23.10 Linux kernel 2.6.23.1 Linux kernel 2.6.23.09 |
| Not Vulnerable: |
Linux kernel 2.6.24 .1 |
Discussion
Linux Kernel Prior to 2.6.24.1 'vmsplice_to_user()' Local Privilege Escalation Vulnerability
The Linux kernel is prone to a privilege-escalation vulnerability because it fails to adequately validate a user-supplied pointer value.
A local attacker can exploit this issue to write to arbitrary memory locations on the affected computer and gain elevated privileges.
This issue affects Linux Kernel 2.6.23 through 2.6.24.
The Linux kernel is prone to a privilege-escalation vulnerability because it fails to adequately validate a user-supplied pointer value.
A local attacker can exploit this issue to write to arbitrary memory locations on the affected computer and gain elevated privileges.
This issue affects Linux Kernel 2.6.23 through 2.6.24.
Exploit / POC
Linux Kernel Prior to 2.6.24.1 'vmsplice_to_user()' Local Privilege Escalation Vulnerability
Exploit code is available.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT v7.5 product. This exploit is not otherwise publicly available.
Exploit code is available.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT v7.5 product. This exploit is not otherwise publicly available.
Solution / Fix
Linux Kernel Prior to 2.6.24.1 'vmsplice_to_user()' Local Privilege Escalation Vulnerability
Solution:
Linux Kernel 2.6.24.1 addresses this issue. Please see the references for more information.
Linux kernel 2.6.23.09
Linux kernel 2.6.23.1
Linux kernel 2.6.24-rc1
Linux kernel 2.6.23.10
Linux kernel 2.6.23.14
Linux kernel 2.6.24-rc2
Linux kernel 2.6.23 .5
Linux kernel 2.6.23 .2
Linux kernel 2.6.23
Linux kernel 2.6.23 -rc2
Linux kernel 2.6.23 .3
Linux kernel 2.6.23 .6
Linux kernel 2.6.23 .4
Linux kernel 2.6.23 .7
Linux kernel 2.6.23 -rc1
Linux kernel 2.6.24 -rc4
Linux kernel 2.6.24 -rc3
Linux kernel 2.6.24 -rc5
Solution:
Linux Kernel 2.6.24.1 addresses this issue. Please see the references for more information.
Linux kernel 2.6.23.09
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.23.1
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.24-rc1
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.23.10
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.23.14
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.24-rc2
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.23 .5
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.23 .2
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.23
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.23 -rc2
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.23 .3
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.23 .6
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.23 .4
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.23 .7
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.23 -rc1
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.24 -rc4
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.24 -rc3
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.24 -rc5
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
References
Linux Kernel Prior to 2.6.24.1 'vmsplice_to_user()' Local Privilege Escalation Vulnerability
References:
References:
- [PATCH] splice: missing user pointer access verification (CVE-2008-0009/10) (Linux)
- Linux 2.6.24.1 Changelog (Kernel.org)
- Linux Homepage (Linux)
- CSA-L03: Linux kernel vmsplice unchecked user-pointer dereference (Wojciech Purczynski)