Linux Kernel Privileged File Descriptor Resource Exhaustion Vulnerability
BID:5178
Info
Linux Kernel Privileged File Descriptor Resource Exhaustion Vulnerability
| Bugtraq ID: | 5178 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 08 2002 12:00AM |
| Updated: | Jul 08 2002 12:00AM |
| Credit: | Published by Paul Starzetz <[email protected]>. |
| Vulnerable: |
Linux kernel 2.4.19 -pre6 Linux kernel 2.4.19 -pre5 Linux kernel 2.4.19 -pre4 Linux kernel 2.4.19 -pre3 Linux kernel 2.4.19 -pre2 Linux kernel 2.4.19 -pre1 Linux kernel 2.4.18 x86 Linux kernel 2.4.18 Linux kernel 2.4.17 Linux kernel 2.4.16 Linux kernel 2.4.15 Linux kernel 2.4.14 Linux kernel 2.4.13 Linux kernel 2.4.12 Linux kernel 2.4.11 Linux kernel 2.4.10 Linux kernel 2.4.9 Linux kernel 2.4.8 Linux kernel 2.4.7 Linux kernel 2.4.6 Linux kernel 2.4.5 Linux kernel 2.4.4 Linux kernel 2.4.3 Linux kernel 2.4.2 Linux kernel 2.4.1 |
| Not Vulnerable: | |
Discussion
Linux Kernel Privileged File Descriptor Resource Exhaustion Vulnerability
The Linux kernel is a freely available, open source kernel originally written by Linus Torvalds. It is the core of all Linux distributions.
Recent versions of the Linux kernel include a collection of file descriptors which are reserved for usage by processes executing as the root user. By default, the size of this collection is set to 10 file descriptors.
It is possible for a local, non-privileged user to open all system file descriptors. The malicious user may then exhaust the pool of reserved descriptors by opening several common suid binaries, resulting in a denial of service condition.
The Linux kernel is a freely available, open source kernel originally written by Linus Torvalds. It is the core of all Linux distributions.
Recent versions of the Linux kernel include a collection of file descriptors which are reserved for usage by processes executing as the root user. By default, the size of this collection is set to 10 file descriptors.
It is possible for a local, non-privileged user to open all system file descriptors. The malicious user may then exhaust the pool of reserved descriptors by opening several common suid binaries, resulting in a denial of service condition.
Exploit / POC
Linux Kernel Privileged File Descriptor Resource Exhaustion Vulnerability
An exploit has been contributed by Paul Starzetz <[email protected]>:
An exploit has been contributed by Paul Starzetz <[email protected]>:
Solution / Fix
Linux Kernel Privileged File Descriptor Resource Exhaustion Vulnerability
Solution:
In addition to resource allocation limits, administrators may wish to modify their kernel source to increase the value of the constant NR_RESERVED_FILES in the file fs.h.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
In addition to resource allocation limits, administrators may wish to modify their kernel source to increase the value of the constant NR_RESERVED_FILES in the file fs.h.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Linux Kernel Privileged File Descriptor Resource Exhaustion Vulnerability
References:
References: