Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20101130010518.GJ23277@ksplice.com>
Date: Mon, 29 Nov 2010 20:05:18 -0500
From: Nelson Elhage <nelhage@...lice.com>
To: oss-security@...ts.openwall.com
Subject: kernel: Multiple vulnerabilities in AF_ECONET

I reported these recently, and they were fixed upstream last week.

CVE-2010-3848: Kernel stack overflow in econet_sendmsg
CVE-2010-3849: NULL pointer dereference in PF_ECONET
CVE-2010-3850: Missing check for capable(CAP_NET_ADMIN) in econet SIOCSIFADDR

CVE-2010-3848 is interesting because it's a bug class I haven't seen before,
although maybe people who have been around longer have. econet_sendmsg() can be
made to allocate > 8192 bytes on the kernel stack, overflowing the two pages
allocated for the stack, and allowing an attacker to clobber the 'struct
thread_info', which provides several easy exploit vectors.

Jon Oberheide has done a more detailed writeup about this bug class here:
http://jon.oberheide.org/blog/2010/11/29/exploiting-stack-overflows-in-the-linux-kernel/

CVE-2010-3850 is mostly interesting because without it, there is no way an
unprivileged user can trigger the first two bugs unless an administrator has
already configured an econet address somewhere (econet_sendmsg fails quickly if
there are no econet addresses configured on the system).

Reference:
http://www.debian.org/security/2010/dsa-2126

Upstream commits:
CVE-2010-3848: http://git.kernel.org/linus/a27e13d370415add3487949c60810e36069a23a6
CVE-2010-3849: http://git.kernel.org/linus/fa0e846494792e722d817b9d3d625a4ef4896c96
CVE-2010-3850: http://git.kernel.org/linus/16c41745c7b92a243d0874f534c1655196c64b74

- Nelson

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.