CVE-2015-3339
published 2015-05-27CVE-2015-3339: Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows local users to gain privileges by executing a setuid…
PriorityP427medium6.2CVSS 2.0
AVLACHAuNCCICAC
EPSS
0.32%
24.2th percentile
Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows local users to gain privileges by executing a setuid program at a time instant when a chown to root is in progress, and the ownership is changed but the setuid bit is not yet stripped.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 3.16.7-ckt9-3 (bookworm) | linux 3.16.7-ckt9-3 (bookworm) |
| linux | linux_kernel | <= 3.19.5 | — |
| linux | linux_kernel | >= 0 < 3.16.7-ckt9-3 | 3.16.7-ckt9-3 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt9-3 | 3.16.7-ckt9-3 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt9-3 | 3.16.7-ckt9-3 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt9-3 | 3.16.7-ckt9-3 |
CVSS provenance
nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
osv6.2MEDIUM
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8x6w-vmh7-xc9h: Race condition in the prepare_binprm function in fs/exec
ghsa_unreviewed·2022-05-17
CVE-2015-3339 [MEDIUM] CWE-362 GHSA-8x6w-vmh7-xc9h: Race condition in the prepare_binprm function in fs/exec
Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows local users to gain privileges by executing a setuid program at a time instant when a chown to root is in progress, and the ownership is changed but the setuid bit is not yet stripped.
OSV
CVE-2015-3339: Race condition in the prepare_binprm function in fs/exec
osv·2015-05-27·CVSS 6.2
CVE-2015-3339 [MEDIUM] CVE-2015-3339: Race condition in the prepare_binprm function in fs/exec
Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows local users to gain privileges by executing a setuid program at a time instant when a chown to root is in progress, and the ownership is changed but the setuid bit is not yet stripped.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2015-05-20·CVSS 4.9
CVE-2014-9715 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A race condition between chown() and execve() was discovered in the Linux
kernel. A local attacker could exploit this race by using chown on a
setuid-user-binary to gain administrative privileges. (CVE-2015-3339)
Vincent Tondellier discovered an integer overflow in the Linux kernel's
netfilter connection tracking accounting of loaded extensions. An attacker
on the local area network (LAN) could potential exploit this flaw to cause
a denial of service (system crash of targeted system). (CVE-2014-9715)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been
Ubuntu
Linux kernel (Trusty HWE) vulnerability
vendor_ubuntu·2015-05-05
CVE-2015-3339 Linux kernel (Trusty HWE) vulnerability
Title: Linux kernel (Trusty HWE) vulnerability
Summary: The system could be made to run programs as an administrator.
A race condition between chown() and execve() was discovered in the Linux
kernel. A local attacker could exploit this race by using chown on a
setuid-user-binary to gain administrative privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled
Ubuntu
Linux kernel (Utopic HWE) vulnerability
vendor_ubuntu·2015-05-05
CVE-2015-3339 Linux kernel (Utopic HWE) vulnerability
Title: Linux kernel (Utopic HWE) vulnerability
Summary: The system could be made to run programs as an administrator.
A race condition between chown() and execve() was discovered in the Linux
kernel. A local attacker could exploit this race by using chown on a
setuid-user-binary to gain administrative privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2015-05-05
CVE-2015-3339 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to run programs as an administrator.
A race condition between chown() and execve() was discovered in the Linux
kernel. A local attacker could exploit this race by using chown on a
setuid-user-binary to gain administrative privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard
Ubuntu
Linux kernel (EC2) vulnerability
vendor_ubuntu·2015-04-30
CVE-2015-3339 Linux kernel (EC2) vulnerability
Title: Linux kernel (EC2) vulnerability
Summary: The system could be made to run programs as an administrator.
A race condition between chown() and execve() was discovered in the Linux
kernel. A local attacker could exploit this race by using chown on a
setuid-user-binary to gain administrative privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the sta
Red Hat
kernel: race condition between chown() and execve()
vendor_redhat·2015-04-20·CVSS 6.2
CVE-2015-3339 [MEDIUM] CWE-362 kernel: race condition between chown() and execve()
kernel: race condition between chown() and execve()
Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows local users to gain privileges by executing a setuid program at a time instant when a chown to root is in progress, and the ownership is changed but the setuid bit is not yet stripped.
A race condition flaw was found between the chown and execve system calls. When changing the owner of a setuid user binary to root, the race condition could momentarily make the binary setuid root. A local, unprivileged user could potentially use this flaw to escalate their privileges on the system.
Statement: This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5 and 7 and MRG-2. This issue is not currently planned to be a
Debian
CVE-2015-3339: linux - Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel b...
vendor_debian·2015·CVSS 6.2
CVE-2015-3339 [MEDIUM] CVE-2015-3339: linux - Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel b...
Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows local users to gain privileges by executing a setuid program at a time instant when a chown to root is in progress, and the ownership is changed but the setuid bit is not yet stripped.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt9-3)
bullseye: resolved (fixed in 3.16.7-ckt9-3)
forky: resolved (fixed in 3.16.7-ckt9-3)
sid: resolved (fixed in 3.16.7-ckt9-3)
trixie: resolved (fixed in 3.16.7-ckt9-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-3339 kernel: race condition between chown() and execve()
bugzilla·2015-04-21·CVSS 6.2
CVE-2015-3339 [MEDIUM] CVE-2015-3339 kernel: race condition between chown() and execve()
CVE-2015-3339 kernel: race condition between chown() and execve()
A race condition flaw was found between the chown() and execve() system calls. When changing the owner of a setuid-user binary to root, the race condition could momentarily make the binary setuid root. When root chown()ed an attacker-owned setuid file to root, the file briefly was setuid root (and executable as such).
An attacker could take advantage of this small window and execute a setuid binary with elevated privileges.
Upstream patch:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8b01fc86b9f425899f8a3a8fc1c47d73c2c20543
Additional details:
http://seclists.org/oss-sec/2015/q2/216
Discussion:
I went ahead and backported this to Fedora. All branches are fixed in git.
---
Statement:
T
arXiv
Timeloops: Automatic System Call Policy Learning for Containerized Microservices
arxiv_fulltext·2022-09-26
Timeloops: Automatic System Call Policy Learning for Containerized Microservices
Meghna Pancholi
[email protected]
Columbia University
Andreas D. Kellas
[email protected]
Columbia University
Vasileios P. Kemerlis
[email protected]
Brown University
Simha Sethumadhavan
[email protected]
Columbia University
## Abstract
We introduce , a novel technique for automatically learning system
call filtering policies for containerized microservices applications. At
run-time, automatically learns which system calls a program should
be allowed to invoke, while rejecting attempts to call spurious system calls.
Further, addresses many of the shortcomings of state-of-the-art
static analysis-based techniques, such as the ability to generate tight filters
for programs written in interpreted languages such as PHP, Python, and
JavaScript. has a simple and rob
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8b01fc86b9f425899f8a3a8fc1c47d73c2c20543http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157897.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/158804.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1272.htmlhttp://www.debian.org/security/2015/dsa-3237http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.19.6http://www.openwall.com/lists/oss-security/2015/04/20/5http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securitytracker.com/id/1032412https://bugzilla.redhat.com/show_bug.cgi?id=1214030https://github.com/torvalds/linux/commit/8b01fc86b9f425899f8a3a8fc1c47d73c2c20543http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8b01fc86b9f425899f8a3a8fc1c47d73c2c20543http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157897.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/158804.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1272.htmlhttp://www.debian.org/security/2015/dsa-3237http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.19.6http://www.openwall.com/lists/oss-security/2015/04/20/5http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securitytracker.com/id/1032412https://bugzilla.redhat.com/show_bug.cgi?id=1214030https://github.com/torvalds/linux/commit/8b01fc86b9f425899f8a3a8fc1c47d73c2c20543
2015-05-27
Published