SecurityTracker.com
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 


Category:   OS (Linux)  >   Linux Kernel Vendors:   kernel.org
Linux Kernel VFS Filesystem Flaw Lets Local Users Deny Service
SecurityTracker Alert ID:  1030991
SecurityTracker URL:  http://securitytracker.com/id/1030991
CVE Reference:   CVE-2014-7970   (Links to External Site)
Date:  Oct 9 2014
Impact:   Denial of service via local system
Fix Available:  Yes  Vendor Confirmed:  Yes  

Description:   A vulnerability was reported in the Linux Kernel. A local user can cause denial of service conditions.

A local user can trigger a mount leak in the VFS filesystem pivot_root() function to cause the target system to crash.

The vulnerability resides in 'fs/namespace.c'.

Andy Lutomirski reported this vulnerability.

Impact:   A local user can cause the target system to crash.
Solution:   A proposed patch is available at:

http://thread.gmane.org/gmane.linux.file-systems/89076

Vendor URL:  www.kernel.org/ (Links to External Site)
Cause:   Access control error, State error

Message History:   None.


 Source Message Contents

Subject:  [oss-security] CVE-2014-7970: Linux VFS denial of service

pivot_root has a bug.  Exploiting it at all is tricky, but it can be
done.  I'm reasonably confident that this is just denial of service.
(There's also probably an information disclosure in there, but I think
that it's only available to root, so it's not a big deal.)

I'm posting this a little bit early, since a patch is publicly
available, the impact is low, and hitting the bad code path at all is
quite tedious.  I'll send a proof of concept later on.

Distros: if you need a test case to validate the fix, let me know.
Although, for validation, it should be sufficient to just chroot
somewhere as root, escape the chroot (while still chrooted), and then
pivot_root(".", ".") on a mountpoint.

Candidate patch here:

http://news.gmane.org/find-root.php?message_id=87bnpmihks.fsf%40x220.int.ebiederm.org

-- 
Andy Lutomirski
AMA Capital Management, LLC
 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2019, SecurityGlobal.net LLC