CVE-2015-8709
published 2016-02-08CVE-2015-8709: kernel/ptrace.c in the Linux kernel through 4.4.1 mishandles uid and gid mappings, which allows local users to gain privileges by establishing a user…
PriorityP433high7CVSS 3.0
AVLACHPRLUINSUCHIHAH
EPSS
0.40%
32.0th percentile
kernel/ptrace.c in the Linux kernel through 4.4.1 mishandles uid and gid mappings, which allows local users to gain privileges by establishing a user namespace, waiting for a root process to enter that namespace with an unsafe uid or gid, and then using the ptrace system call. NOTE: the vendor states "there is no kernel bug here.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.3.3-3 (bookworm) | linux 4.3.3-3 (bookworm) |
| linux | linux_kernel | <= 4.4.1 | — |
| linux | linux_kernel | >= 0 < 4.3.3-3 | 4.3.3-3 |
| linux | linux_kernel | >= 0 < 4.3.3-3 | 4.3.3-3 |
| linux | linux_kernel | >= 0 < 4.3.3-3 | 4.3.3-3 |
| linux | linux_kernel | >= 0 < 4.3.3-3 | 4.3.3-3 |
| linux | linux_kernel | >= 0 < 3.13.0-74.118 | 3.13.0-74.118 |
CVSS provenance
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv8.2HIGH
vendor_ubuntu8.2HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Wily HWE) vulnerabilities
vendor_ubuntu·2015-12-20·CVSS 8.2
CVE-2015-8550 [HIGH] Linux kernel (Wily HWE) vulnerabilities
Title: Linux kernel (Wily HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on the host.
(CVE-2015-8550)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service (NULL dereference) on the host.
(CVE-2015-8551)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities
vendor_ubuntu·2015-12-20·CVSS 8.2
CVE-2015-8550 [HIGH] Linux kernel (Vivid HWE) vulnerabilities
Title: Linux kernel (Vivid HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on the host.
(CVE-2015-8550)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service (NULL dereference) on the host.
(CVE-2015-8551)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw t
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2015-12-19·CVSS 8.2
CVE-2015-8550 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on the host.
(CVE-2015-8550)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service (NULL dereference) on the host.
(CVE-2015-8551)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerability
vendor_ubuntu·2015-12-19·CVSS 7.0
CVE-2015-8709 [HIGH] Linux kernel (Raspberry Pi 2) vulnerability
Title: Linux kernel (Raspberry Pi 2) vulnerability
Summary: The system could be made to provide access outside of namespace sandbox.
Jann Horn discovered a ptrace issue with user namespaces in the Linux
kernel. The namespace owner could potentially exploit this flaw by ptracing
a root owned process entering the user namespace to elevate its privileges
and potentially gain access outside of the namespace.
(http://bugs.launchpad.net/bugs/1527374, CVE-2015-8709)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manu
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-12-19·CVSS 8.2
CVE-2015-8550 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on the host.
(CVE-2015-8550)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service (NULL dereference) on the host.
(CVE-2015-8551)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a de
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2015-12-19·CVSS 8.2
CVE-2015-8550 [HIGH] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on the host.
(CVE-2015-8550)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service (NULL dereference) on the host.
(CVE-2015-8551)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw
Red Hat
Kernel: ptrace: potential privilege escalation in user namespaces
vendor_redhat·2015-12-12·CVSS 7.0
CVE-2015-8709 [HIGH] CWE-271 Kernel: ptrace: potential privilege escalation in user namespaces
Kernel: ptrace: potential privilege escalation in user namespaces
kernel/ptrace.c in the Linux kernel through 4.4.1 mishandles uid and gid mappings, which allows local users to gain privileges by establishing a user namespace, waiting for a root process to enter that namespace with an unsafe uid or gid, and then using the ptrace system call. NOTE: the vendor states "there is no kernel bug here.
A privilege-escalation vulnerability was discovered in the Linux kernel built with User Namespace (CONFIG_USER_NS) support. The flaw occurred when the ptrace() system call was used on a root-owned process to enter a user namespace. A privileged namespace user could exploit this flaw to potentially escalate their privileges on the system, outside the original namespace.
Statement: This issue does
Debian
CVE-2015-8709: linux - kernel/ptrace.c in the Linux kernel through 4.4.1 mishandles uid and gid mapping...
vendor_debian·2015·CVSS 7.0
CVE-2015-8709 [HIGH] CVE-2015-8709: linux - kernel/ptrace.c in the Linux kernel through 4.4.1 mishandles uid and gid mapping...
kernel/ptrace.c in the Linux kernel through 4.4.1 mishandles uid and gid mappings, which allows local users to gain privileges by establishing a user namespace, waiting for a root process to enter that namespace with an unsafe uid or gid, and then using the ptrace system call. NOTE: the vendor states "there is no kernel bug here.
Scope: local
bookworm: resolved (fixed in 4.3.3-3)
bullseye: resolved (fixed in 4.3.3-3)
forky: resolved (fixed in 4.3.3-3)
sid: resolved (fixed in 4.3.3-3)
trixie: resolved (fixed in 4.3.3-3)
GHSA
GHSA-fpp6-vh8j-3rgm: ** DISPUTED ** kernel/ptrace
ghsa_unreviewed·2022-05-17
CVE-2015-8709 [HIGH] GHSA-fpp6-vh8j-3rgm: ** DISPUTED ** kernel/ptrace
** DISPUTED ** kernel/ptrace.c in the Linux kernel through 4.4.1 mishandles uid and gid mappings, which allows local users to gain privileges by establishing a user namespace, waiting for a root process to enter that namespace with an unsafe uid or gid, and then using the ptrace system call. NOTE: the vendor states "there is no kernel bug here."
OSV
CVE-2015-8709: kernel/ptrace
osv·2016-02-08·CVSS 7.0
CVE-2015-8709 [HIGH] CVE-2015-8709: kernel/ptrace
kernel/ptrace.c in the Linux kernel through 4.4.1 mishandles uid and gid mappings, which allows local users to gain privileges by establishing a user namespace, waiting for a root process to enter that namespace with an unsafe uid or gid, and then using the ptrace system call. NOTE: the vendor states "there is no kernel bug here.
OSV
linux-lts-wily vulnerabilities
osv·2015-12-20·CVSS 8.2
CVE-2015-8550 [HIGH] linux-lts-wily vulnerabilities
linux-lts-wily vulnerabilities
Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on the host.
(CVE-2015-8550)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service (NULL dereference) on the host.
(CVE-2015-8551)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service by flooding the logging system with
WARN() messag
OSV
linux-lts-vivid vulnerabilities
osv·2015-12-20·CVSS 8.2
CVE-2015-8550 [HIGH] linux-lts-vivid vulnerabilities
linux-lts-vivid vulnerabilities
Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on the host.
(CVE-2015-8550)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service (NULL dereference) on the host.
(CVE-2015-8551)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service by flooding the logging system with
WARN() messa
OSV
linux-lts-utopic vulnerabilities
osv·2015-12-19·CVSS 8.2
CVE-2015-8550 [HIGH] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on the host.
(CVE-2015-8550)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service (NULL dereference) on the host.
(CVE-2015-8551)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service by flooding the logging system with
WARN() mess
OSV
linux vulnerabilities
osv·2015-12-19·CVSS 8.2
CVE-2015-8550 [HIGH] linux vulnerabilities
linux vulnerabilities
Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on the host.
(CVE-2015-8550)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service (NULL dereference) on the host.
(CVE-2015-8551)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service by flooding the logging system with
WARN() messages causin
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8709 Kernel: ptrace: potential privilege escalation in user namespaces
bugzilla·2016-01-04·CVSS 7.0
CVE-2015-8709 [HIGH] CVE-2015-8709 Kernel: ptrace: potential privilege escalation in user namespaces
CVE-2015-8709 Kernel: ptrace: potential privilege escalation in user namespaces
Linux kernel built with the User Namespaces(CONFIG_USER_NS) support is
vulnerable to a potential privilege escalation flaw. It could occur when a
root owned process tries to enter a user namespace, wherein a user attempts
to attach the entering process via ptrace(1).
A privileged name space user could use this flaw to potentially escalate their
privileges on the system.
Upstream fix:
-> https://lkml.org/lkml/2015/12/25/71
Reference:
-> http://seclists.org/oss-sec/2015/q4/614
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1295288]
---
Statement:
This issue does not affect the versions of the kernel package as shipped with
Red Hat Enterprise Linux 5, 6, 7 and Red Hat E
Bugzilla
CVE-2015-8709 Kernel: ptrace: potential privilege escalation in user namespaces [fedora-all]
bugzilla·2016-01-04·CVSS 7.0
CVE-2015-8709 [HIGH] CVE-2015-8709 Kernel: ptrace: potential privilege escalation in user namespaces [fedora-all]
CVE-2015-8709 Kernel: ptrace: potential privilege escalation in user namespaces [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple support
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176484.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00030.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00036.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00037.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.htmlhttp://marc.info/?l=linux-kernel&m=145204362722256&w=2http://marc.info/?l=linux-kernel&m=145204641422813&w=2http://www.debian.org/security/2016/dsa-3434http://www.openwall.com/lists/oss-security/2015/12/17/12http://www.openwall.com/lists/oss-security/2015/12/31/5http://www.securityfocus.com/bid/79899http://www.securitytracker.com/id/1034899https://bugzilla.redhat.com/show_bug.cgi?id=1295287https://lkml.org/lkml/2015/12/25/71http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176484.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00030.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00036.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00037.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.htmlhttp://marc.info/?l=linux-kernel&m=145204362722256&w=2http://marc.info/?l=linux-kernel&m=145204641422813&w=2http://www.debian.org/security/2016/dsa-3434http://www.openwall.com/lists/oss-security/2015/12/17/12http://www.openwall.com/lists/oss-security/2015/12/31/5http://www.securityfocus.com/bid/79899http://www.securitytracker.com/id/1034899https://bugzilla.redhat.com/show_bug.cgi?id=1295287https://lkml.org/lkml/2015/12/25/71
2016-02-08
Published