CVE-2015-1420
published 2015-03-16CVE-2015-1420: Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and…
PriorityP47low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.36%
29.1th percentile
Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read operations on additional memory locations by changing the handle_bytes value of a file handle during the execution of this function.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | linux | < linux 3.16.7-ckt7-1 (bookworm) | linux 3.16.7-ckt7-1 (bookworm) |
| linux | linux_kernel | <= 3.18.9 | — |
| linux | linux_kernel | >= 0 < 3.16.7-ckt7-1 | 3.16.7-ckt7-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt7-1 | 3.16.7-ckt7-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt7-1 | 3.16.7-ckt7-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt7-1 | 3.16.7-ckt7-1 |
| linux | linux_kernel | >= 0 < 3.13.0-57.95 | 3.13.0-57.95 |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv6.9MEDIUM
vendor_ubuntu6.9MEDIUM
vendor_debian1.9LOW
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-88mg-hqxv-95h4: Race condition in the handle_to_path function in fs/fhandle
ghsa_unreviewed·2022-05-17
CVE-2015-1420 [LOW] CWE-362 GHSA-88mg-hqxv-95h4: Race condition in the handle_to_path function in fs/fhandle
Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read operations on additional memory locations by changing the handle_bytes value of a file handle during the execution of this function.
OSV
linux-lts-vivid vulnerabilities
osv·2015-07-07·CVSS 1.9
CVE-2015-1420 [LOW] linux-lts-vivid vulnerabilities
linux-lts-vivid vulnerabilities
A race condition was discovered in the Linux kernel's file_handle size
verification. A local user could exploit this flaw to read potentially
sensative memory locations. (CVE-2015-1420)
A underflow error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4001)
A bounds check error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4002)
A division by zero
OSV
linux vulnerabilities
osv·2015-07-07·CVSS 6.9
CVE-2014-9710 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Alexandre Oliva reported a race condition flaw in the btrfs file system's
handling of extended attributes (xattrs). A local attacker could exploit
this flaw to bypass ACLs and potentially escalate privileges.
(CVE-2014-9710)
A race condition was discovered in the Linux kernel's file_handle size
verification. A local user could exploit this flaw to read potentially
sensative memory locations. (CVE-2015-1420)
A underflow error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4001)
A bounds check error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi
OSV
linux-lts-utopic vulnerabilities
osv·2015-07-07·CVSS 1.9
CVE-2015-1420 [LOW] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
A race condition was discovered in the Linux kernel's file_handle size
verification. A local user could exploit this flaw to read potentially
sensative memory locations. (CVE-2015-1420)
A underflow error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4001)
A bounds check error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4002)
A division by zero
OSV
CVE-2015-1420: Race condition in the handle_to_path function in fs/fhandle
osv·2015-03-16·CVSS 1.9
CVE-2015-1420 [LOW] CVE-2015-1420: Race condition in the handle_to_path function in fs/fhandle
Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read operations on additional memory locations by changing the handle_bytes value of a file handle during the execution of this function.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-07-07·CVSS 6.9
CVE-2014-9710 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Alexandre Oliva reported a race condition flaw in the btrfs file system's
handling of extended attributes (xattrs). A local attacker could exploit
this flaw to bypass ACLs and potentially escalate privileges.
(CVE-2014-9710)
A race condition was discovered in the Linux kernel's file_handle size
verification. A local user could exploit this flaw to read potentially
sensative memory locations. (CVE-2015-1420)
A underflow error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4001)
A bounds ch
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2015-07-07·CVSS 1.9
CVE-2015-1420 [LOW] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A race condition was discovered in the Linux kernel's file_handle size
verification. A local user could exploit this flaw to read potentially
sensative memory locations. (CVE-2015-1420)
A underflow error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4001)
A bounds check error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitr
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2015-07-07
CVE-2015-1420 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to expose sensitive information over the
local applications.
A race condition was discovered in the Linux kernel's file_handle size
verification. A local user could exploit this flaw to read potentially
sensative memory locations.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard ker
Ubuntu
Linux kernel (OMAP4) vulnerability
vendor_ubuntu·2015-07-07
CVE-2015-1420 Linux kernel (OMAP4) vulnerability
Title: Linux kernel (OMAP4) vulnerability
Summary: The system could be made to expose sensitive information to local
applications.
A race condition was discovered in the Linux kernel's file_handle size
verification. A local user could exploit this flaw to read potentially
sensative memory locations.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard k
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities
vendor_ubuntu·2015-07-07·CVSS 1.9
CVE-2015-1420 [LOW] Linux kernel (Vivid HWE) vulnerabilities
Title: Linux kernel (Vivid HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A race condition was discovered in the Linux kernel's file_handle size
verification. A local user could exploit this flaw to read potentially
sensative memory locations. (CVE-2015-1420)
A underflow error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4001)
A bounds check error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitra
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-07-07·CVSS 1.9
CVE-2015-1420 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A race condition was discovered in the Linux kernel's file_handle size
verification. A local user could exploit this flaw to read potentially
sensative memory locations. (CVE-2015-1420)
A underflow error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4001)
A bounds check error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2015-07-07·CVSS 6.9
CVE-2014-9710 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Alexandre Oliva reported a race condition flaw in the btrfs file system's
handling of extended attributes (xattrs). A local attacker could exploit
this flaw to bypass ACLs and potentially escalate privileges.
(CVE-2014-9710)
A race condition was discovered in the Linux kernel's file_handle size
verification. A local user could exploit this flaw to read potentially
sensative memory locations. (CVE-2015-1420)
A underflow error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4001)
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-07-07·CVSS 1.9
CVE-2015-1420 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A race condition was discovered in the Linux kernel's file_handle size
verification. A local user could exploit this flaw to read potentially
sensative memory locations. (CVE-2015-1420)
A underflow error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4001)
A bounds check error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via
Red Hat
kernel: fs/fhandle.c race condition
vendor_redhat·2015-01-28·CVSS 1.9
CVE-2015-1420 [LOW] CWE-841 kernel: fs/fhandle.c race condition
kernel: fs/fhandle.c race condition
Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read operations on additional memory locations by changing the handle_bytes value of a file handle during the execution of this function.
Statement: This problem does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5. This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 6, 7 and Red Hat Enterprise MRG-2 kernels.
This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/su
Debian
CVE-2015-1420: linux - Race condition in the handle_to_path function in fs/fhandle.c in the Linux kerne...
vendor_debian·2015·CVSS 1.9
CVE-2015-1420 [LOW] CVE-2015-1420: linux - Race condition in the handle_to_path function in fs/fhandle.c in the Linux kerne...
Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read operations on additional memory locations by changing the handle_bytes value of a file handle during the execution of this function.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt7-1)
bullseye: resolved (fixed in 3.16.7-ckt7-1)
forky: resolved (fixed in 3.16.7-ckt7-1)
sid: resolved (fixed in 3.16.7-ckt7-1)
trixie: resolved (fixed in 3.16.7-ckt7-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1420 kernel: fs/fhandle.c race condition [fedora-all]
bugzilla·2015-06-02·CVSS 1.9
CVE-2015-1420 [LOW] CVE-2015-1420 kernel: fs/fhandle.c race condition [fedora-all]
CVE-2015-1420 kernel: fs/fhandle.c race condition [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While o
Bugzilla
CVE-2015-1420 kernel: fs/fhandle.c race condition
bugzilla·2015-01-30·CVSS 1.9
CVE-2015-1420 [LOW] CVE-2015-1420 kernel: fs/fhandle.c race condition
CVE-2015-1420 kernel: fs/fhandle.c race condition
A specially crafted user space application may exploit a bug in handle_to_path to copy additional data to a target application. This defect is caused by the kernel incorrectly assuming that the arguments provided do not change.
This is problematic since the kernel does size verifications only after the first
read, so if the number of extra bytes changes in userspace between the first
and second calls, we'll have an incoherent view of file_handle.
The fix is to read the size once, and copy that over to the final
structure referencing it from that point rather than the value from the application which may change.
The patch is not yet present in official kernel tree:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/log/fs/fh
arXiv
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
arxiv_fulltext·2022-04-26
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
## Abstract
This paper presents a systematic study on the security of modern file systems,
following a vulnerability-centric perspective. Specifically,
we collected 377 file system vulnerabilities committed to the CVE database in the past 20 years.
We characterize them from four dimensions that include why the vulnerabilities appear,
how the vulnerabilities can be exploited, what consequences can arise,
and how the vulnerabilities are fixed. This way, we build a deep understanding of
the attack surfaces faced by file systems, the threats imposed by the attack surfaces,
and the good and bad practices in mitigating the attacks in file systems. We envision that our study
will bring insights toward
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.htmlhttp://marc.info/?l=linux-kernel&m=142247707318982&w=2http://www.debian.org/security/2015/dsa-3170http://www.openwall.com/lists/oss-security/2015/01/29/12http://www.securityfocus.com/bid/72357http://www.ubuntu.com/usn/USN-2660-1http://www.ubuntu.com/usn/USN-2661-1http://www.ubuntu.com/usn/USN-2665-1http://www.ubuntu.com/usn/USN-2667-1https://bugzilla.redhat.com/show_bug.cgi?id=1187534http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.htmlhttp://marc.info/?l=linux-kernel&m=142247707318982&w=2http://www.debian.org/security/2015/dsa-3170http://www.openwall.com/lists/oss-security/2015/01/29/12http://www.securityfocus.com/bid/72357http://www.ubuntu.com/usn/USN-2660-1http://www.ubuntu.com/usn/USN-2661-1http://www.ubuntu.com/usn/USN-2665-1http://www.ubuntu.com/usn/USN-2667-1https://bugzilla.redhat.com/show_bug.cgi?id=1187534
2015-03-16
Published