CVE-2015-7837
published 2017-09-19CVE-2015-7837: The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to…
PriorityP423medium5.5CVSS 3.0
AVLACLPRLUINSUCNIHAN
EPSS
0.40%
32.8th percentile
The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handling of secure_boot flag across kexec reboot.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.5.1-1 (bookworm) | linux 4.5.1-1 (bookworm) |
| linux | linux_kernel | >= 0 < 4.5.1-1 | 4.5.1-1 |
| linux | linux_kernel | >= 0 < 4.5.1-1 | 4.5.1-1 |
| linux | linux_kernel | >= 0 < 4.5.1-1 | 4.5.1-1 |
| linux | linux_kernel | >= 0 < 4.5.1-1 | 4.5.1-1 |
| linux | linux_kernel | >= 0 < 4.4.0-93.116 | 4.4.0-93.116 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_mrg | — | — |
| redhat | kernel-rt | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2017-08-28·CVSS 5.5
CVE-2015-7837 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3405-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that a use-after-free vulnerability existed in the POSIX
message queue implementation in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-11176)
Huang Weller discovered that the ext4 filesystem implementation in the
Linux kernel mishandled a needs-flushing-before-commit list. A local
attacker could use this to expose sensitive information. (CVE-2017-7495)
I
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-08-28·CVSS 5.5
CVE-2015-7837 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a use-after-free vulnerability existed in the POSIX
message queue implementation in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-11176)
Huang Weller discovered that the ext4 filesystem implementation in the
Linux kernel mishandled a needs-flushing-before-commit list. A local
attacker could use this to expose sensitive information. (CVE-2017-7495)
It was discovered that a buffer overflow existed in the Broadcom FullMAC
WLAN driver in the Linux kernel. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2017-
Red Hat
kernel: securelevel disabled after kexec
vendor_redhat·2015-10-14·CVSS 5.5
CVE-2015-7837 [MEDIUM] CWE-456 kernel: securelevel disabled after kexec
kernel: securelevel disabled after kexec
The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handling of secure_boot flag across kexec reboot.
A flaw was found in the way the Linux kernel handled the securelevel functionality after performing a kexec operation. A local attacker could use this flaw to bypass the security mechanism of the securelevel/secureboot combination.
Statement: This issue does not affect the Linux kernels as shipped with Red Hat Enterprise Linux 5 and 6.
This issue affects the Linux kernels as shipped with Red Hat Enterprise Linux 7, kernel-rt and MRG-2.
Package: kernel (Red Hat Enterpr
Debian
CVE-2015-7837: linux - The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterpri...
vendor_debian·2015·CVSS 5.5
CVE-2015-7837 [MEDIUM] CVE-2015-7837: linux - The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterpri...
The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handling of secure_boot flag across kexec reboot.
Scope: local
bookworm: resolved (fixed in 4.5.1-1)
bullseye: resolved (fixed in 4.5.1-1)
forky: resolved (fixed in 4.5.1-1)
sid: resolved (fixed in 4.5.1-1)
trixie: resolved (fixed in 4.5.1-1)
GHSA
GHSA-3cqh-r98g-rhgh: The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local u
ghsa_unreviewed·2022-05-13
CVE-2015-7837 [MEDIUM] GHSA-3cqh-r98g-rhgh: The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local u
The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handling of secure_boot flag across kexec reboot.
OSV
CVE-2015-7837: The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local u
osv·2017-09-19·CVSS 5.5
CVE-2015-7837 [MEDIUM] CVE-2015-7837: The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local u
The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handling of secure_boot flag across kexec reboot.
OSV
linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities
osv·2017-08-28·CVSS 5.5
CVE-2017-11176 [MEDIUM] linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that a use-after-free vulnerability existed in the POSIX
message queue implementation in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-11176)
Huang Weller discovered that the ext4 filesystem implementation in the
Linux kernel mishandled a needs-flushing-before-commit list. A local
attacker could use this to expose sensitive information. (CVE-2017-7495)
It was discovered that a buffer overflow existed in the Broadcom FullMAC
WLAN driver in the Linux kernel. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2017-7541)
It was discovered t
OSV
linux-lts-xenial vulnerabilities
osv·2017-08-28·CVSS 5.5
CVE-2017-11176 [MEDIUM] linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
USN-3405-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that a use-after-free vulnerability existed in the POSIX
message queue implementation in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-11176)
Huang Weller discovered that the ext4 filesystem implementation in the
Linux kernel mishandled a needs-flushing-before-commit list. A local
attacker could use this to expose sensitive information. (CVE-2017-7495)
It was discovered that a buffer overflow existed in the Broadcom FullMAC
WLAN drive
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-7837 kernel: securelevel disabled after kexec
bugzilla·2015-10-16·CVSS 5.5
CVE-2015-7837 [MEDIUM] CVE-2015-7837 kernel: securelevel disabled after kexec
CVE-2015-7837 kernel: securelevel disabled after kexec
A vulnerability was found in kexec, allowing the attacker to bypass the security mechanism of securelevel/secureboot combination.
When the kernel was booted with UEFI Secure Boot enabled, securelevel is set. If kexec (either through crash or admin action) is then used to load the same kernel, after reboot securelevel is disabled. In this state, the system is missing the protections provided by securelevel, for example kexec may be used to load an unsigned kernel via the legacy system call kexec_load. In the securelevel patchset, the state of UEFI Secure Boot is queried in the EFI stub, and sets a boot_params flag to indicate the state of UEFI Secure Boot. This flag is then used in setup_arch() to determine the correct state of secure
Bugzilla
CVE-2015-7837 kernel: securelevel disabled after kexec [rhel-7.2]
bugzilla·2015-07-16·CVSS 5.5
CVE-2015-7837 [MEDIUM] CVE-2015-7837 kernel: securelevel disabled after kexec [rhel-7.2]
CVE-2015-7837 kernel: securelevel disabled after kexec [rhel-7.2]
Created attachment 1052836
patch
Description of problem:
When RHEL 7.1 is booted with UEFI Secure Boot enabled, securelevel is set. If kexec is then used to load the same kernel, after reboot securelevel is disabled. In this state, the system is missing the protections provided by securelevel, for example kexec may be used to load an unsigned kernel via the legacy system call kexec_load.
In the securelevel patchset, the state of UEFI Secure Boot is queried in the EFI stub, and sets a boot_params flag to indicate the state of UEFI Secure Boot. This flag is then used in setup_arch() to determine the correct state of securelevel. If the kernel is not booted via the EFI stub, securelevel is not set even if UEFI Secure Boot i
http://rhn.redhat.com/errata/RHSA-2015-2152.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2411.htmlhttp://www.openwall.com/lists/oss-security/2015/10/15/6http://www.securityfocus.com/bid/77097https://bugzilla.redhat.com/show_bug.cgi?id=1272472https://github.com/mjg59/linux/commit/4b2b64d5a6ebc84214755ebccd599baef7c1b798http://rhn.redhat.com/errata/RHSA-2015-2152.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2411.htmlhttp://www.openwall.com/lists/oss-security/2015/10/15/6http://www.securityfocus.com/bid/77097https://bugzilla.redhat.com/show_bug.cgi?id=1272472https://github.com/mjg59/linux/commit/4b2b64d5a6ebc84214755ebccd599baef7c1b798
2017-09-19
Published