CVE-2004-1058
published 2005-01-10CVE-2004-1058: Race condition in Linux kernel 2.6 allows local users to read the environment variables of another process that is still spawning via /proc/.../cmdline.
PriorityP48low1.2CVSS 2.0
AVLACHAuNCPINAN
EPSS
0.39%
32.1th percentile
Race condition in Linux kernel 2.6 allows local users to read the environment variables of another process that is still spawning via /proc/.../cmdline.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| ubuntu | ubuntu_linux | — | — |
CVSS provenance
nvdv2.01.2LOWAV:L/AC:H/Au:N/C:P/I:N/A:N
vendor_redhat1.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2004-12-15
CVE-2004-1137 Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
CAN-2004-0814:
Vitaly V. Bursov discovered a Denial of Service vulnerability in the "serio"
code; opening the same tty device twice and doing some particular operations on
it caused a kernel panic and/or a system lockup.
Fixing this vulnerability required a change in the Application Binary
Interface (ABI) of the kernel. This means that third party user installed
modules might not work any more with the new kernel, so this fixed kernel got
a new ABI version number. You have to recompile and reinstall all third party
modules.
CAN-2004-1016:
Paul Starzetz discovered a buffer overflow vulnerability in the "__scm_send"
function which handles the sending of UDP network packets. A wrong validity
check of the cmsghdr s
Red Hat
security flaw
vendor_redhat·2004-08-23·CVSS 1.2
CVE-2004-1058 [LOW] security flaw
security flaw
Race condition in Linux kernel 2.6 allows local users to read the environment variables of another process that is still spawning via /proc/.../cmdline.
GHSA
GHSA-m29m-89vm-949f: Race condition in Linux kernel 2
ghsa_unreviewed·2022-05-03
CVE-2004-1058 [LOW] GHSA-m29m-89vm-949f: Race condition in Linux kernel 2
Race condition in Linux kernel 2.6 allows local users to read the environment variables of another process that is still spawning via /proc/.../cmdline.
No detection rules found.
Bugzilla
CVE-2004-1058 security flaw
bugzilla·2018-08-16·CVSS 1.2
CVE-2004-1058 [LOW] CVE-2004-1058 security flaw
CVE-2004-1058 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Race condition in Linux kernel 2.6 allows local users to read the environment variables of another process that is still spawning via /proc/.../cmdline.
Bugzilla
CVE-2004-1058 /proc/<PID>/cmdline information disclosure
bugzilla·2004-09-21·CVSS 1.2
CVE-2004-1058 [LOW] CVE-2004-1058 /proc/<PID>/cmdline information disclosure
CVE-2004-1058 /proc//cmdline information disclosure
There's a race in the kernel, and considering the permissions on
/proc/PID/{cmdline,environ} a security bug as well: If you win the
race with a starting process, you can read its environment.
http://lkml.org/lkml/2004/7/29/332
Discussion:
Might be 2.6 only
fixed in 2.6.9
http://linux.bkbits.net:8080/linux-2.6/cset@412a4baaEebwtKg-X7sS2r5Mua6uGw
---
I believe RHEL2.1 isn't affected by this flaw and RHEL3 is only
affected because of a backported patch. Moving to NEEDINFO for a
kernel engineer to verify.
---
It looks like this was corrected for RHEL3, but RHEL21 is still vulnerable.
---
Created attachment 118875
Backport proc_pid_cmdline() fix from RHEL3.
---
An advisory has been issued which should help the problem
described in
Bugzilla
CVE-2004-1058 /proc/<PID>/cmdline information disclosure
bugzilla·2004-09-21·CVSS 1.2
CVE-2004-1058 [LOW] CVE-2004-1058 /proc/<PID>/cmdline information disclosure
CVE-2004-1058 /proc//cmdline information disclosure
There's a race in the kernel, and considering the permissions on
/proc/PID/{cmdline,environ} a security bug as well: If you win the
race with a starting process, you can read its environment.
http://lkml.org/lkml/2004/7/29/332
Discussion:
Might be 2.6 only
fixed in 2.6.9
http://linux.bkbits.net:8080/linux-2.6/cset@412a4baaEebwtKg-X7sS2r5Mua6uGw
---
I believe RHEL2.1 isn't affected by this flaw and RHEL3 is only
affected because of a backported patch. Moving to NEEDINFO for a
kernel engineer to verify.
---
Derry needs this fix. See pensacola BZ 133115 for patch.
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more in
ftp://patches.sgi.com/support/free/security/advisories/20060402-01-Uhttp://lists.suse.de/archive/suse-security-announce/2006-Feb/0010.htmlhttp://secunia.com/advisories/18684http://secunia.com/advisories/19038http://secunia.com/advisories/19369http://secunia.com/advisories/19607http://secunia.com/advisories/21476http://www.debian.org/security/2006/dsa-1018http://www.gentoo.org/security/en/glsa/glsa-200408-24.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:022http://www.redhat.com/support/errata/RHSA-2005-293.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0190.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0191.htmlhttp://www.securityfocus.com/bid/11052http://www.securityfocus.com/bid/11937https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532https://exchange.xforce.ibmcloud.com/vulnerabilities/17151https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10427https://usn.ubuntu.com/38-1/ftp://patches.sgi.com/support/free/security/advisories/20060402-01-Uhttp://lists.suse.de/archive/suse-security-announce/2006-Feb/0010.htmlhttp://secunia.com/advisories/18684http://secunia.com/advisories/19038http://secunia.com/advisories/19369http://secunia.com/advisories/19607http://secunia.com/advisories/21476http://www.debian.org/security/2006/dsa-1018http://www.gentoo.org/security/en/glsa/glsa-200408-24.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:022http://www.redhat.com/support/errata/RHSA-2005-293.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0190.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0191.htmlhttp://www.securityfocus.com/bid/11052http://www.securityfocus.com/bid/11937https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532https://exchange.xforce.ibmcloud.com/vulnerabilities/17151https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10427https://usn.ubuntu.com/38-1/
2005-01-10
Published