CVE-2015-7613
published 2015-10-19CVE-2015-7613: Race condition in the IPC object implementation in the Linux kernel through 4.2.3 allows local users to gain privileges by triggering an ipc_addid call that…
PriorityP425medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.41%
33.9th percentile
Race condition in the IPC object implementation in the Linux kernel through 4.2.3 allows local users to gain privileges by triggering an ipc_addid call that leads to uid and gid comparisons against uninitialized data, related to msg.c, shm.c, and util.c.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.2.3-1 (bookworm) | linux 4.2.3-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | < 3.2.72 | 3.2.72 |
| linux | linux_kernel | >= 0 < 4.2.3-1 | 4.2.3-1 |
| linux | linux_kernel | >= 0 < 4.2.3-1 | 4.2.3-1 |
| linux | linux_kernel | >= 0 < 4.2.3-1 | 4.2.3-1 |
| linux | linux_kernel | >= 0 < 4.2.3-1 | 4.2.3-1 |
| linux | linux_kernel | >= 3.11 < 3.12.50 | 3.12.50 |
| linux | linux_kernel | >= 3.13 < 3.14.55 | 3.14.55 |
| linux | linux_kernel | >= 3.15 < 3.16.35 | 3.16.35 |
| linux | linux_kernel | >= 3.17 < 3.18.23 | 3.18.23 |
| linux | linux_kernel | >= 3.19 < 4.1.11 | 4.1.11 |
| linux | linux_kernel | >= 3.3 < 3.4.111 | 3.4.111 |
| linux | linux_kernel | >= 3.5 < 3.10.91 | 3.10.91 |
| linux | linux_kernel | >= 4.2 < 4.2.4 | 4.2.4 |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-11-05·CVSS 5.0
CVE-2015-0272 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dmitry Vyukov discovered that the Linux kernel did not properly initialize
IPC object state in certain situations. A local attacker could use this to
escalate their privileges, expose confidential information, or cause a
denial of service (system crash). (CVE-2015-7613)
It was discovered that the Linux kernel did not check if a new IPv6 MTU set
by a user space application was valid. A remote attacker could forge a
route advertisement with an invalid MTU that a user space daemon like
NetworkManager would honor and apply to the kernel, causing a denial of
service. (CVE-2015-0272)
It was discovered that in certain situations, a directory could be renamed
outside of a bind mounted location. An at
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2015-11-05·CVSS 5.0
CVE-2015-0272 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dmitry Vyukov discovered that the Linux kernel did not properly initialize
IPC object state in certain situations. A local attacker could use this to
escalate their privileges, expose confidential information, or cause a
denial of service (system crash). (CVE-2015-7613)
It was discovered that the Linux kernel did not check if a new IPv6 MTU set
by a user space application was valid. A remote attacker could forge a
route advertisement with an invalid MTU that a user space daemon like
NetworkManager would honor and apply to the kernel, causing a denial of
service. (CVE-2015-0272)
It was discovered that in certain situations, a directory could be renamed
outside of a bind mounted locatio
Ubuntu
Linux kernel (Utopic HWE) vulnerability
vendor_ubuntu·2015-10-05
CVE-2015-7613 Linux kernel (Utopic HWE) vulnerability
Title: Linux kernel (Utopic HWE) vulnerability
Summary: The system could be made to crash or run programs as an administrator.
Dmitry Vyukov discovered that the Linux kernel did not properly initialize
IPC object state in certain situations. A local attacker could use this to
escalate their privileges, expose confidential information, or cause a
denial of service (system crash).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2015-10-05
CVE-2015-7613 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash or run programs as an administrator.
Dmitry Vyukov discovered that the Linux kernel did not properly initialize
IPC object state in certain situations. A local attacker could use this to
escalate their privileges, expose confidential information, or cause a
denial of service (system crash).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with th
Ubuntu
Linux kernel (Trusty HWE) vulnerability
vendor_ubuntu·2015-10-05
CVE-2015-7613 Linux kernel (Trusty HWE) vulnerability
Title: Linux kernel (Trusty HWE) vulnerability
Summary: The system could be made to crash or run programs as an administrator.
Dmitry Vyukov discovered that the Linux kernel did not properly initialize
IPC object state in certain situations. A local attacker could use this to
escalate their privileges, expose confidential information, or cause a
denial of service (system crash).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which
Ubuntu
Linux kernel (Vivid HWE) vulnerability
vendor_ubuntu·2015-10-05
CVE-2015-7613 Linux kernel (Vivid HWE) vulnerability
Title: Linux kernel (Vivid HWE) vulnerability
Summary: The system could be made to crash or run programs as an administrator.
Dmitry Vyukov discovered that the Linux kernel did not properly initialize
IPC object state in certain situations. A local attacker could use this to
escalate their privileges, expose confidential information, or cause a
denial of service (system crash).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which
Red Hat
kernel: Unauthorized access to IPC objects with SysV shm
vendor_redhat·2015-10-01·CVSS 6.9
CVE-2015-7613 [MEDIUM] CWE-732 kernel: Unauthorized access to IPC objects with SysV shm
kernel: Unauthorized access to IPC objects with SysV shm
Race condition in the IPC object implementation in the Linux kernel through 4.2.3 allows local users to gain privileges by triggering an ipc_addid call that leads to uid and gid comparisons against uninitialized data, related to msg.c, shm.c, and util.c.
A race condition flaw was found in the way the Linux kernel's IPC subsystem initialized certain fields in an IPC object structure that were later used for permission checking before inserting the object into a globally visible list. A local, unprivileged user could potentially use this flaw to elevate their privileges on the system.
Statement: This issue does not affect the Linux kernels as shipped with Red Hat Enterprise Linux 5.
This issue affects the Linux kernels as shipped wi
Debian
CVE-2015-7613: linux - Race condition in the IPC object implementation in the Linux kernel through 4.2....
vendor_debian·2015·CVSS 6.9
CVE-2015-7613 [MEDIUM] CVE-2015-7613: linux - Race condition in the IPC object implementation in the Linux kernel through 4.2....
Race condition in the IPC object implementation in the Linux kernel through 4.2.3 allows local users to gain privileges by triggering an ipc_addid call that leads to uid and gid comparisons against uninitialized data, related to msg.c, shm.c, and util.c.
Scope: local
bookworm: resolved (fixed in 4.2.3-1)
bullseye: resolved (fixed in 4.2.3-1)
forky: resolved (fixed in 4.2.3-1)
sid: resolved (fixed in 4.2.3-1)
trixie: resolved (fixed in 4.2.3-1)
GHSA
GHSA-c9h8-jpjh-qq7q: Race condition in the IPC object implementation in the Linux kernel through 4
ghsa_unreviewed·2022-05-17
CVE-2015-7613 [MEDIUM] CWE-362 GHSA-c9h8-jpjh-qq7q: Race condition in the IPC object implementation in the Linux kernel through 4
Race condition in the IPC object implementation in the Linux kernel through 4.2.3 allows local users to gain privileges by triggering an ipc_addid call that leads to uid and gid comparisons against uninitialized data, related to msg.c, shm.c, and util.c.
GHSA
GHSA-7hfg-g948-3x2h: The System V IPC implementation in the kernel in Android before 6
ghsa_unreviewed·2022-05-17·CVSS 6.9
CVE-2015-6646 [MEDIUM] GHSA-7hfg-g948-3x2h: The System V IPC implementation in the kernel in Android before 6
The System V IPC implementation in the kernel in Android before 6.0 2016-01-01 allows attackers to cause a denial of service (global kernel resource consumption) by leveraging improper interaction between IPC resource allocation and the memory manager, aka internal bug 22300191, a different vulnerability than CVE-2015-7613.
OSV
CVE-2015-6646: The System V IPC implementation in the kernel in Android before 6
osv·2016-01-06·CVSS 6.2
CVE-2015-6646 [MEDIUM] CVE-2015-6646: The System V IPC implementation in the kernel in Android before 6
The System V IPC implementation in the kernel in Android before 6.0 2016-01-01 allows attackers to cause a denial of service (global kernel resource consumption) by leveraging improper interaction between IPC resource allocation and the memory manager, aka internal bug 22300191, a different vulnerability than CVE-2015-7613.
OSV
CVE-2015-7613: Race condition in the IPC object implementation in the Linux kernel through 4
osv·2015-10-19·CVSS 6.9
CVE-2015-7613 [MEDIUM] CVE-2015-7613: Race condition in the IPC object implementation in the Linux kernel through 4
Race condition in the IPC object implementation in the Linux kernel through 4.2.3 allows local users to gain privileges by triggering an ipc_addid call that leads to uid and gid comparisons against uninitialized data, related to msg.c, shm.c, and util.c.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-7613 kernel: Unauthorized access to IPC objects with SysV shm [fedora-all]
bugzilla·2015-10-02·CVSS 6.9
CVE-2015-7613 [MEDIUM] CVE-2015-7613 kernel: Unauthorized access to IPC objects with SysV shm [fedora-all]
CVE-2015-7613 kernel: Unauthorized access to IPC objects with SysV shm [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
Bugzilla
CVE-2015-7613 kernel: Unauthorized access to IPC objects with SysV shm
bugzilla·2015-10-02·CVSS 6.9
CVE-2015-7613 [MEDIUM] CVE-2015-7613 kernel: Unauthorized access to IPC objects with SysV shm
CVE-2015-7613 kernel: Unauthorized access to IPC objects with SysV shm
A data race that can trick the kernel into using initialized memory was found. This vulnerability can at least give access to arbitrary SysV shared memory. It is almost certain that this vulnerability can be used to gain arbitrary code execution in the kernel.
While working on KTSAN, Dmitry Vyukov got a report that says that ipc_addid() installs a not-completely initialized object into the shared object table. In particular, uid/gid are not initialized. ipc_obtain_object_check() in turn obtains the object and verifies uid/gid for permission purposes. Since the fields are not initialized, the check can falsely succeed.
Race report:
ThreadSanitizer: data-race in ipc_obtain_object_check
Read at 0xffff88047f810f68 of s
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b9a532277938798b53178d5a66af6e2915cb27cfhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00030.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00032.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2636.htmlhttp://www.debian.org/security/2015/dsa-3372http://www.openwall.com/lists/oss-security/2015/10/01/8http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/76977http://www.securitytracker.com/id/1034094http://www.securitytracker.com/id/1034592http://www.ubuntu.com/usn/USN-2761-1http://www.ubuntu.com/usn/USN-2762-1http://www.ubuntu.com/usn/USN-2763-1http://www.ubuntu.com/usn/USN-2764-1http://www.ubuntu.com/usn/USN-2765-1http://www.ubuntu.com/usn/USN-2792-1https://bugzilla.redhat.com/show_bug.cgi?id=1268270https://github.com/torvalds/linux/commit/b9a532277938798b53178d5a66af6e2915cb27cfhttps://kc.mcafee.com/corporate/index?page=content&id=SB10146http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b9a532277938798b53178d5a66af6e2915cb27cfhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00030.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00032.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2636.htmlhttp://www.debian.org/security/2015/dsa-3372http://www.openwall.com/lists/oss-security/2015/10/01/8http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/76977http://www.securitytracker.com/id/1034094http://www.securitytracker.com/id/1034592http://www.ubuntu.com/usn/USN-2761-1http://www.ubuntu.com/usn/USN-2762-1http://www.ubuntu.com/usn/USN-2763-1http://www.ubuntu.com/usn/USN-2764-1http://www.ubuntu.com/usn/USN-2765-1http://www.ubuntu.com/usn/USN-2792-1https://bugzilla.redhat.com/show_bug.cgi?id=1268270https://github.com/torvalds/linux/commit/b9a532277938798b53178d5a66af6e2915cb27cfhttps://kc.mcafee.com/corporate/index?page=content&id=SB10146
2015-10-19
Published