CVE-2015-1593
published 2015-03-16CVE-2015-1593: The stack randomization feature in the Linux kernel before 3.19.1 on 64-bit platforms uses incorrect data types for the results of bitwise left-shift…
PriorityP429medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
3.81%
89.0th percentile
The stack randomization feature in the Linux kernel before 3.19.1 on 64-bit platforms uses incorrect data types for the results of bitwise left-shift operations, which makes it easier for attackers to bypass the ASLR protection mechanism by predicting the address of the top of the stack, related to the randomize_stack_top function in fs/binfmt_elf.c and the stack_maxrandom_size function in arch/x86/mm/mmap.c.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.16.7-ckt7-1 (bookworm) | linux 3.16.7-ckt7-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | <= 3.18.9 | — |
| linux | linux_kernel | >= 0 < 3.16.7-ckt7-1 | 3.16.7-ckt7-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt7-1 | 3.16.7-ckt7-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt7-1 | 3.16.7-ckt7-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt7-1 | 3.16.7-ckt7-1 |
| linux | linux_kernel | >= 0 < 3.13.0-49.81 | 3.13.0-49.81 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv10.0CRITICAL
vendor_ubuntu10.0CRITICAL
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2015-1593: Android Security Bulletin 2016-08-01
CVE: CVE-2015-1593
Severity: HIGH
References: A-29577822
Upstream kernel
vendor_android·2016-08-01·CVSS 5.0
CVE-2015-1593 [MEDIUM] CVE-2015-1593: Android Security Bulletin 2016-08-01
CVE: CVE-2015-1593
Severity: HIGH
References: A-29577822
Upstream kernel
Android Security Bulletin 2016-08-01
CVE: CVE-2015-1593
Severity: HIGH
References: A-29577822
Upstream kernel
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-04-09·CVSS 5.0
CVE-2015-1593 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
An integer overflow was discovered in the stack randomization feature of
the Linux kernel on 64 bit platforms. A local attacker could exploit this
flaw to bypass the Address Space Layout Randomization (ASLR) protection
mechanism. (CVE-2015-1593)
An information leak was discovered in the Linux Kernel's handling of
userspace configuration of the link layer control (LLC). A local user could
exploit this flaw to read data from other sysctl settings. (CVE-2015-2041)
An information leak was discovered in how the Linux kernel handles setting
the Reliable Datagram Sockets (RDS) settings. A local user could exploit
this flaw to read data from other sysctl settings. (CVE-2015-2042)
A memory corruption
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2015-04-09·CVSS 5.0
CVE-2015-1593 [MEDIUM] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
An integer overflow was discovered in the stack randomization feature of
the Linux kernel on 64 bit platforms. A local attacker could exploit this
flaw to bypass the Address Space Layout Randomization (ASLR) protection
mechanism. (CVE-2015-1593)
An information leak was discovered in the Linux Kernel's handling of
userspace configuration of the link layer control (LLC). A local user could
exploit this flaw to read data from other sysctl settings. (CVE-2015-2041)
An information leak was discovered in how the Linux kernel handles setting
the Reliable Datagram Sockets (RDS) settings. A local user could exploit
this flaw to read data from other sysctl settings. (CVE-2015-2042)
A memo
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2015-04-08·CVSS 6.9
CVE-2014-8159 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the Linux kernel's Infiniband subsystem did not
properly sanitize its input parameters while registering memory regions
from userspace. A local user could exploit this flaw to cause a denial of
service (system crash) or to potentially gain administrative privileges.
(CVE-2014-8159)
An integer overflow was discovered in the stack randomization feature of
the Linux kernel on 64 bit platforms. A local attacker could exploit this
flaw to bypass the Address Space Layout Randomization (ASLR) protection
mechanism. (CVE-2015-1593)
An information leak was discovered in the Linux Kernel's handling of
userspace configuration of the link layer control (LLC). A local user co
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-04-08·CVSS 10.0
CVE-2015-1421 [CRITICAL] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Sun Baoliang discovered a use after free flaw in the Linux kernel's SCTP
(Stream Control Transmission Protocol) subsystem during INIT collisions. A
remote attacker could exploit this flaw to cause a denial of service
(system crash) or potentially escalate their privileges on the system.
(CVE-2015-1421)
Marcelo Leitner discovered a flaw in the Linux kernel's routing of packets
to too many different dsts/too fast. A remote attacker on the same subnet can exploit this
flaw to cause a denial of service (system crash). (CVE-2015-1465)
An integer overflow was discovered in the stack randomization feature of
the Linux kernel on 64 bit platforms. A local attacker could exploit this
flaw to bypass the
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2015-04-08·CVSS 10.0
CVE-2015-1421 [CRITICAL] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Sun Baoliang discovered a use after free flaw in the Linux kernel's SCTP
(Stream Control Transmission Protocol) subsystem during INIT collisions. A
remote attacker could exploit this flaw to cause a denial of service
(system crash) or potentially escalate their privileges on the system.
(CVE-2015-1421)
Marcelo Leitner discovered a flaw in the Linux kernel's routing of packets
to too many different dsts/too fast. A remote attacker on the same subnet can exploit this
flaw to cause a denial of service (system crash). (CVE-2015-1465)
An integer overflow was discovered in the stack randomization feature of
the Linux kernel on 64 bit platforms. A local attacker could exploit this
flaw
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-04-08·CVSS 5.0
CVE-2015-1593 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
An integer overflow was discovered in the stack randomization feature of
the Linux kernel on 64 bit platforms. A local attacker could exploit this
flaw to bypass the Address Space Layout Randomization (ASLR) protection
mechanism. (CVE-2015-1593)
An information leak was discovered in the Linux Kernel's handling of
userspace configuration of the link layer control (LLC). A local user could
exploit this flaw to read data from other sysctl settings. (CVE-2015-2041)
An information leak was discovered in how the Linux kernel handles setting
the Reliable Datagram Sockets (RDS) settings. A local user could exploit
this flaw to read data from other sysctl settings. (CVE-2015-2042)
Instructions: After
Red Hat
kernel: Linux stack ASLR implementation Integer overflow
vendor_redhat·2015-02-13·CVSS 5.0
CVE-2015-1593 [MEDIUM] CWE-190 kernel: Linux stack ASLR implementation Integer overflow
kernel: Linux stack ASLR implementation Integer overflow
The stack randomization feature in the Linux kernel before 3.19.1 on 64-bit platforms uses incorrect data types for the results of bitwise left-shift operations, which makes it easier for attackers to bypass the ASLR protection mechanism by predicting the address of the top of the stack, related to the randomize_stack_top function in fs/binfmt_elf.c and the stack_maxrandom_size function in arch/x86/mm/mmap.c.
An integer overflow flaw was found in the way the Linux kernel randomized the stack for processes on certain 64-bit architecture systems, such as x86-64, causing the stack entropy to be reduced by four.
Statement: This issue does affect the Linux kernel versions as shipped with Red Hat Enterprise Linux 6, 7 and Red Hat Enterp
Debian
CVE-2015-1593: linux - The stack randomization feature in the Linux kernel before 3.19.1 on 64-bit plat...
vendor_debian·2015·CVSS 5.0
CVE-2015-1593 [MEDIUM] CVE-2015-1593: linux - The stack randomization feature in the Linux kernel before 3.19.1 on 64-bit plat...
The stack randomization feature in the Linux kernel before 3.19.1 on 64-bit platforms uses incorrect data types for the results of bitwise left-shift operations, which makes it easier for attackers to bypass the ASLR protection mechanism by predicting the address of the top of the stack, related to the randomize_stack_top function in fs/binfmt_elf.c and the stack_maxrandom_size function in arch/x86/mm/mmap.c.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt7-1)
bullseye: resolved (fixed in 3.16.7-ckt7-1)
forky: resolved (fixed in 3.16.7-ckt7-1)
sid: resolved (fixed in 3.16.7-ckt7-1)
trixie: resolved (fixed in 3.16.7-ckt7-1)
GHSA
GHSA-6qcg-g8hp-m564: The stack randomization feature in the Linux kernel before 3
ghsa_unreviewed·2022-05-14
CVE-2015-1593 [MEDIUM] GHSA-6qcg-g8hp-m564: The stack randomization feature in the Linux kernel before 3
The stack randomization feature in the Linux kernel before 3.19.1 on 64-bit platforms uses incorrect data types for the results of bitwise left-shift operations, which makes it easier for attackers to bypass the ASLR protection mechanism by predicting the address of the top of the stack, related to the randomize_stack_top function in fs/binfmt_elf.c and the stack_maxrandom_size function in arch/x86/mm/mmap.c.
OSV
linux-lts-utopic vulnerabilities
osv·2015-04-09·CVSS 5.0
CVE-2015-1593 [MEDIUM] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
An integer overflow was discovered in the stack randomization feature of
the Linux kernel on 64 bit platforms. A local attacker could exploit this
flaw to bypass the Address Space Layout Randomization (ASLR) protection
mechanism. (CVE-2015-1593)
An information leak was discovered in the Linux Kernel's handling of
userspace configuration of the link layer control (LLC). A local user could
exploit this flaw to read data from other sysctl settings. (CVE-2015-2041)
An information leak was discovered in how the Linux kernel handles setting
the Reliable Datagram Sockets (RDS) settings. A local user could exploit
this flaw to read data from other sysctl settings. (CVE-2015-2042)
A memory corruption flaw was discovered in the Linux kernel's scsi
subsystem. A lo
OSV
linux vulnerabilities
osv·2015-04-08·CVSS 10.0
CVE-2015-1421 [CRITICAL] linux vulnerabilities
linux vulnerabilities
Sun Baoliang discovered a use after free flaw in the Linux kernel's SCTP
(Stream Control Transmission Protocol) subsystem during INIT collisions. A
remote attacker could exploit this flaw to cause a denial of service
(system crash) or potentially escalate their privileges on the system.
(CVE-2015-1421)
Marcelo Leitner discovered a flaw in the Linux kernel's routing of packets
to too many different dsts/too fast. A remote attacker on the same subnet can exploit this
flaw to cause a denial of service (system crash). (CVE-2015-1465)
An integer overflow was discovered in the stack randomization feature of
the Linux kernel on 64 bit platforms. A local attacker could exploit this
flaw to bypass the Address Space Layout Randomization (ASLR) protection
mechanism. (CVE-2015
OSV
CVE-2015-1593: The stack randomization feature in the Linux kernel before 3
osv·2015-03-16·CVSS 5.0
CVE-2015-1593 [MEDIUM] CVE-2015-1593: The stack randomization feature in the Linux kernel before 3
The stack randomization feature in the Linux kernel before 3.19.1 on 64-bit platforms uses incorrect data types for the results of bitwise left-shift operations, which makes it easier for attackers to bypass the ASLR protection mechanism by predicting the address of the top of the stack, related to the randomize_stack_top function in fs/binfmt_elf.c and the stack_maxrandom_size function in arch/x86/mm/mmap.c.
Kernel
x86, mm/ASLR: Fix stack randomization on 64-bit systems
kernel_security·2015-02-14
CVE-2015-1593 x86, mm/ASLR: Fix stack randomization on 64-bit systems
x86, mm/ASLR: Fix stack randomization on 64-bit systems
The issue is that the stack for processes is not properly randomized on
64 bit architectures due to an integer overflow.
The affected function is randomize_stack_top() in file
"fs/binfmt_elf.c":
static unsigned long randomize_stack_top(unsigned long stack_top)
{
unsigned int random_variable = 0;
if ((current->flags & PF_RANDOMIZE) &&
!(current->personality & ADDR_NO_RANDOMIZE)) {
random_variable = get_random_int() & STACK_RND_MASK;
random_variable
Signed-off-by: Ismael Ripoll
[ Rebased, fixed 80 char bugs, cleaned up commit message, added test example and CVE ]
Signed-off-by: Kees Cook
Cc:
Cc: Linus Torvalds
Cc: Andrew Morton
Cc: Al Viro
Fixes: CVE-2015-1593
Link: http://lkml.kernel.org/r/[email protected]
Sig
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1593 kernel: Linux stack ASLR implementation Integer overflow
bugzilla·2015-02-13·CVSS 5.0
CVE-2015-1593 [MEDIUM] CVE-2015-1593 kernel: Linux stack ASLR implementation Integer overflow
CVE-2015-1593 kernel: Linux stack ASLR implementation Integer overflow
It was reported [1] that stack address is not properly randomized on some 64 bit architectures due to an integer overflow.
The stack entropy of the processes is reduced by four.
The possible locations are significantly reduced from around one billion to two hundred millions. The problem seems to affect only to the x86_64 architecture.
Proposed patch:
https://lkml.org/lkml/2015/1/7/811
[1]: http://hmarco.org/bugs/linux-ASLR-integer-overflow.html
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1192520]
---
Statement:
This issue does affect the Linux kernel versions as shipped with Red Hat Enterprise Linux 6, 7 and Red Hat Enterprise MRG 2. Future kernel updates in the respective r
Bugzilla
CVE-2015-1593 kernel: Linux stack ASLR implementation Integer overflow [fedora-all]
bugzilla·2015-02-13·CVSS 5.0
CVE-2015-1593 [MEDIUM] CVE-2015-1593 kernel: Linux stack ASLR implementation Integer overflow [fedora-all]
CVE-2015-1593 kernel: Linux stack ASLR implementation Integer overflow [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=4e7c22d447bb6d7e37bfe39ff658486ae78e8d77http://hmarco.org/bugs/linux-ASLR-integer-overflow.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1137.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1138.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1221.htmlhttp://www.debian.org/security/2015/dsa-3170http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.19.1http://www.openwall.com/lists/oss-security/2015/02/13/13http://www.securityfocus.com/bid/72607http://www.ubuntu.com/usn/USN-2560-1http://www.ubuntu.com/usn/USN-2561-1http://www.ubuntu.com/usn/USN-2562-1http://www.ubuntu.com/usn/USN-2563-1http://www.ubuntu.com/usn/USN-2564-1http://www.ubuntu.com/usn/USN-2565-1https://access.redhat.com/errata/RHSA-2019:3517https://bugzilla.redhat.com/show_bug.cgi?id=1192519https://github.com/torvalds/linux/commit/4e7c22d447bb6d7e37bfe39ff658486ae78e8d77https://lkml.org/lkml/2015/1/7/811http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=4e7c22d447bb6d7e37bfe39ff658486ae78e8d77http://hmarco.org/bugs/linux-ASLR-integer-overflow.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1137.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1138.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1221.htmlhttp://www.debian.org/security/2015/dsa-3170http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.19.1http://www.openwall.com/lists/oss-security/2015/02/13/13http://www.securityfocus.com/bid/72607http://www.ubuntu.com/usn/USN-2560-1http://www.ubuntu.com/usn/USN-2561-1http://www.ubuntu.com/usn/USN-2562-1http://www.ubuntu.com/usn/USN-2563-1http://www.ubuntu.com/usn/USN-2564-1http://www.ubuntu.com/usn/USN-2565-1https://access.redhat.com/errata/RHSA-2019:3517https://bugzilla.redhat.com/show_bug.cgi?id=1192519https://github.com/torvalds/linux/commit/4e7c22d447bb6d7e37bfe39ff658486ae78e8d77https://lkml.org/lkml/2015/1/7/811
2015-03-16
Published