Linux Kernel 'sys_remap_file_pages()' Local Privilege Escalation Vulnerability
BID:33211
Info
Linux Kernel 'sys_remap_file_pages()' Local Privilege Escalation Vulnerability
| Bugtraq ID: | 33211 |
| Class: | Design Error |
| CVE: |
CVE-2009-0024 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 12 2009 12:00AM |
| Updated: | Jan 13 2009 04:22PM |
| Credit: | Nelson Elhage |
| Vulnerable: |
Linux kernel 2.6.24 -rc5 Linux kernel 2.6.24 -rc4 Linux kernel 2.6.24 -rc3 Linux kernel 2.6.24 -git13 Linux kernel 2.6.24-rc2 Linux kernel 2.6.24-rc1 |
| Not Vulnerable: |
Linux kernel 2.6.24 .1 |
Discussion
Linux Kernel 'sys_remap_file_pages()' Local Privilege Escalation Vulnerability
The Linux kernel is prone to a local privilege-escalation vulnerability.
A local attacker can exploit this issue to execute arbitrary code with superuser privileges. A successful exploit will result in the complete compromise of affected computers. Failed exploit attempts will result in a denial-of-service condition.
Versions prior to Linux kernel 2.6.24.1 are vulnerable.
The Linux kernel is prone to a local privilege-escalation vulnerability.
A local attacker can exploit this issue to execute arbitrary code with superuser privileges. A successful exploit will result in the complete compromise of affected computers. Failed exploit attempts will result in a denial-of-service condition.
Versions prior to Linux kernel 2.6.24.1 are vulnerable.
Exploit / POC
Linux Kernel 'sys_remap_file_pages()' Local Privilege Escalation Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Linux Kernel 'sys_remap_file_pages()' Local Privilege Escalation Vulnerability
Solution:
The vendor addressed this issue in Linux kernel 2.6.24. Please see the references for more information.
Linux kernel 2.6.24-rc2
Linux kernel 2.6.24-rc1
Linux kernel 2.6.24 -rc4
Linux kernel 2.6.24 -rc3
Linux kernel 2.6.24 -rc5
Solution:
The vendor addressed this issue in Linux kernel 2.6.24. Please see the references for more information.
Linux kernel 2.6.24-rc2
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.24-rc1
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.24 -rc4
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.24 -rc3
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.24 -rc5
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
References
Linux Kernel 'sys_remap_file_pages()' Local Privilege Escalation Vulnerability
References:
References:
- CVE-2009-0024 kernel: local privilege escalation in sys_remap_file_pages (Eugene Teo)
- Linux 2.6.24.1 Changelog (Kernel.org)
- Linux Homepage (Linux)