Linux Kernel 'keys/gc.c' Local Memory Corruption Vulnerability
BID:71880
Info
Linux Kernel 'keys/gc.c' Local Memory Corruption Vulnerability
| Bugtraq ID: | 71880 |
| Class: | Race Condition Error |
| CVE: |
CVE-2014-9529 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 06 2015 12:00AM |
| Updated: | Sep 07 2016 04:00PM |
| Credit: | Sasha Levin |
| Vulnerable: |
Ubuntu Ubuntu Linux 14.10 Ubuntu Ubuntu Linux 14.04 LTS Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 12.04 LTS Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 S.u.S.E. openSUSE 13.2 S.u.S.E. openSUSE 13.1 Redhat MRG Realtime for RHEL 6 Server 2 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server EUS 6.6.z Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux Desktop 6 Pexip Pexip Infinity 8.0 Pexip Pexip Infinity 7.0 Pexip Pexip Infinity 6.0 Pexip Pexip Infinity 5.0 Pexip Pexip Infinity 4.0 Pexip Pexip Infinity 3.0 Pexip Pexip Infinity 2.0 Pexip Pexip Infinity 1.0 Oracle Enterprise Linux 7 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 Linux kernel Google Nexus Player 0 Google Nexus 9 Google Nexus 6 Google Nexus 5 Google Android One 0 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 7 CentOS CentOS 6 |
| Not Vulnerable: |
Pexip Pexip Infinity 9.0 |
Discussion
Linux Kernel 'keys/gc.c' Local Memory Corruption Vulnerability
The Linux kernel is prone to a local memory-corruption vulnerability.
A local attacker may exploit this issue to cause a kernel panic, denying service to legitimate users.
The Linux kernel is prone to a local memory-corruption vulnerability.
A local attacker may exploit this issue to cause a kernel panic, denying service to legitimate users.
Exploit / POC
Linux Kernel 'keys/gc.c' Local Memory Corruption Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Linux Kernel 'keys/gc.c' Local Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
-
Mandriva cpupower-3.4.105-2.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva kernel-firmware-3.4.105-2.1.mbs1.noarch.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva kernel-headers-3.4.105-2.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva kernel-server-3.4.105-2.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva kernel-server-devel-3.4.105-2.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva kernel-source-3.4.105-2.mbs1.noarch.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64cpupower-devel-3.4.105-2.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64cpupower0-3.4.105-2.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva perf-3.4.105-2.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
Linux Kernel 'keys/gc.c' Local Memory Corruption Vulnerability
References:
References:
- [PATCH] KEYS: close race between key lookup and freeing (marc)
- Linux Homepage (Linux)
- Android Security Bulletin�??September 2016 (Google)
- CVE-2014-9529 - Linux kernel security/keys/gc.c race condition (SecLists.Org)
- KEYS: close race between key lookup and freeing (Git)
- pexip Security Bulletin: Multiple vulnerabilities (Pexip)
- Security Advisory Important: kernel security and bug fix update (Red Hat)