CVE-2016-7042
published 2016-10-16CVE-2016-7042: The proc_keys_show function in security/keys/proc.c in the Linux kernel through 4.8.2, when the GNU Compiler Collection (gcc) stack protector is enabled, uses…
PriorityP422medium6.2CVSS 3.0
AVLACLPRNUINSUCNINAH
EPSS
0.40%
32.2th percentile
The proc_keys_show function in security/keys/proc.c in the Linux kernel through 4.8.2, when the GNU Compiler Collection (gcc) stack protector is enabled, uses an incorrect buffer size for certain timeout data, which allows local users to cause a denial of service (stack memory corruption and panic) by reading the /proc/keys file.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.7.8-1 (bookworm) | linux 4.7.8-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | <= 4.8.2 | — |
| linux | linux_kernel | >= 0 < 4.7.8-1 | 4.7.8-1 |
| linux | linux_kernel | >= 0 < 4.7.8-1 | 4.7.8-1 |
| linux | linux_kernel | >= 0 < 4.7.8-1 | 4.7.8-1 |
| linux | linux_kernel | >= 0 < 4.7.8-1 | 4.7.8-1 |
| linux | linux_kernel | >= 0 < 3.13.0-101.148 | 3.13.0-101.148 |
CVSS provenance
nvdv3.06.2MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2016-7042: Android Security Bulletin 2017-01-01
CVE: CVE-2016-7042
Severity: HIGH
References: A-32178986
Upstream kernel
vendor_android·2017-01-01·CVSS 6.2
CVE-2016-7042 [MEDIUM] CVE-2016-7042: Android Security Bulletin 2017-01-01
CVE: CVE-2016-7042
Severity: HIGH
References: A-32178986
Upstream kernel
Android Security Bulletin 2017-01-01
CVE: CVE-2016-7042
Severity: HIGH
References: A-32178986
Upstream kernel
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2016-12-20·CVSS 5.5
CVE-2015-8964 [MEDIUM] Linux kernel (Raspberry Pi 2) vulnerabilities
Title: Linux kernel (Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Tilman Schmidt and Sasha Levin discovered a use-after-free condition in the
TTY implementation in the Linux kernel. A local attacker could use this to
expose sensitive information (kernel memory). (CVE-2015-8964)
It was discovered that the Video For Linux Two (v4l2) implementation in the
Linux kernel did not properly handle multiple planes when processing a
VIDIOC_DQBUF ioctl(). A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2016-4568)
CAI Qian discovered that shared bind mounts in a mount namespace
exponentially added entries without restriction to the Linux kernel's mount
table. A local attacker could use
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-11-11·CVSS 6.2
CVE-2016-7042 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ondrej Kozina discovered that the keyring interface in the Linux kernel
contained a buffer overflow when displaying timeout events via the
/proc/keys interface. A local attacker could use this to cause a denial of
service (system crash). (CVE-2016-7042)
Dmitry Vyukov discovered a use-after-free vulnerability during error
processing in the recvmmsg(2) implementation in the Linux kernel. A remote
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2016-7117)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
b
Ubuntu
Linux kernel (Xenial HWE) vulnerability
vendor_ubuntu·2016-11-11
CVE-2016-7042 Linux kernel (Xenial HWE) vulnerability
Title: Linux kernel (Xenial HWE) vulnerability
Summary: The system could be made to crash under certain conditions.
USN-3128-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Ondrej Kozina discovered that the keyring interface in the Linux kernel
contained a buffer overflow when displaying timeout events via the
/proc/keys interface. A local attacker could use this to cause a denial of
service (system crash).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-11-11·CVSS 7.8
CVE-2014-9904 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the compression handling code in the Advanced Linux
Sound Architecture (ALSA) subsystem in the Linux kernel did not properly
check for an integer overflow. A local attacker could use this to cause a
denial of service (system crash). (CVE-2014-9904)
Kirill A. Shutemov discovered that memory manager in the Linux kernel did
not properly handle anonymous pages. A local attacker could use this to
cause a denial of service or possibly gain administrative privileges.
(CVE-2015-3288)
Vitaly Kuznetsov discovered that the Linux kernel did not properly suppress
hugetlbfs support in X86 paravirtualized guests. An attacker in the guest
OS could cause a denial of service (guest syste
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2016-11-11
CVE-2016-7042 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash under certain conditions.
Ondrej Kozina discovered that the keyring interface in the Linux kernel
contained a buffer overflow when displaying timeout events via the
/proc/keys interface. A local attacker could use this to cause a denial of
service (system crash).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powe
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2016-11-11·CVSS 6.2
CVE-2016-7042 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ondrej Kozina discovered that the keyring interface in the Linux kernel
contained a buffer overflow when displaying timeout events via the
/proc/keys interface. A local attacker could use this to cause a denial of
service (system crash). (CVE-2016-7042)
Dmitry Vyukov discovered a use-after-free vulnerability during error
processing in the recvmmsg(2) implementation in the Linux kernel. A remote
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2016-7117)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel update
Ubuntu
Linux kernel (Qualcomm Snapdragon) vulnerability
vendor_ubuntu·2016-11-11
CVE-2016-7042 Linux kernel (Qualcomm Snapdragon) vulnerability
Title: Linux kernel (Qualcomm Snapdragon) vulnerability
Summary: The system could be made to crash under certain conditions.
Ondrej Kozina discovered that the keyring interface in the Linux kernel
contained a buffer overflow when displaying timeout events via the
/proc/keys interface. A local attacker could use this to cause a denial of
service (system crash).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, lin
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2016-11-11·CVSS 7.8
CVE-2014-9904 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
USN-3127-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 LTS.
It was discovered that the compression handling code in the Advanced Linux
Sound Architecture (ALSA) subsystem in the Linux kernel did not properly
check for an integer overflow. A local attacker could use this to cause a
denial of service (system crash). (CVE-2014-9904)
Kirill A. Shutemov discovered that memory manager in the Linux kernel did
not properly handle anonymous pages. A local attacker could use this to
cause a denial of service or possibly gain administrative
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2016-11-11·CVSS 6.2
CVE-2016-7042 [MEDIUM] Linux kernel (Raspberry Pi 2) vulnerabilities
Title: Linux kernel (Raspberry Pi 2) vulnerabilities
Summary: The system could be made to crash under certain conditions.
Ondrej Kozina discovered that the keyring interface in the Linux kernel
contained a buffer overflow when displaying timeout events via the
/proc/keys interface. A local attacker could use this to cause a denial of
service (system crash). (CVE-2016-7042)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts
Red Hat
kernel: Stack corruption while reading /proc/keys when gcc stack protector is enabled
vendor_redhat·2016-10-13·CVSS 6.2
CVE-2016-7042 [MEDIUM] CWE-121 kernel: Stack corruption while reading /proc/keys when gcc stack protector is enabled
kernel: Stack corruption while reading /proc/keys when gcc stack protector is enabled
The proc_keys_show function in security/keys/proc.c in the Linux kernel through 4.8.2, when the GNU Compiler Collection (gcc) stack protector is enabled, uses an incorrect buffer size for certain timeout data, which allows local users to cause a denial of service (stack memory corruption and panic) by reading the /proc/keys file.
It was found that when the gcc stack protector was enabled, reading the /proc/keys file could cause a panic in the Linux kernel due to stack corruption. This happened because an incorrect buffer size was used to hold a 64-bit timeout value rendered as weeks.
Statement: This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5. This has been rated
Debian
CVE-2016-7042: linux - The proc_keys_show function in security/keys/proc.c in the Linux kernel through ...
vendor_debian·2016·CVSS 6.2
CVE-2016-7042 [MEDIUM] CVE-2016-7042: linux - The proc_keys_show function in security/keys/proc.c in the Linux kernel through ...
The proc_keys_show function in security/keys/proc.c in the Linux kernel through 4.8.2, when the GNU Compiler Collection (gcc) stack protector is enabled, uses an incorrect buffer size for certain timeout data, which allows local users to cause a denial of service (stack memory corruption and panic) by reading the /proc/keys file.
Scope: local
bookworm: resolved (fixed in 4.7.8-1)
bullseye: resolved (fixed in 4.7.8-1)
forky: resolved (fixed in 4.7.8-1)
sid: resolved (fixed in 4.7.8-1)
trixie: resolved (fixed in 4.7.8-1)
GHSA
GHSA-qx4h-3xrh-8hmg: The proc_keys_show function in security/keys/proc
ghsa_unreviewed·2022-05-14
CVE-2016-7042 [MEDIUM] CWE-119 GHSA-qx4h-3xrh-8hmg: The proc_keys_show function in security/keys/proc
The proc_keys_show function in security/keys/proc.c in the Linux kernel through 4.8.2, when the GNU Compiler Collection (gcc) stack protector is enabled, uses an incorrect buffer size for certain timeout data, which allows local users to cause a denial of service (stack memory corruption and panic) by reading the /proc/keys file.
OSV
linux-raspi2 vulnerabilities
osv·2016-12-20·CVSS 5.5
CVE-2015-8964 [MEDIUM] linux-raspi2 vulnerabilities
linux-raspi2 vulnerabilities
Tilman Schmidt and Sasha Levin discovered a use-after-free condition in the
TTY implementation in the Linux kernel. A local attacker could use this to
expose sensitive information (kernel memory). (CVE-2015-8964)
It was discovered that the Video For Linux Two (v4l2) implementation in the
Linux kernel did not properly handle multiple planes when processing a
VIDIOC_DQBUF ioctl(). A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2016-4568)
CAI Qian discovered that shared bind mounts in a mount namespace
exponentially added entries without restriction to the Linux kernel's mount
table. A local attacker could use this to cause a denial of service (system
crash). (CVE-2016-6213)
Ondrej Kozina di
OSV
linux vulnerabilities
osv·2016-11-11·CVSS 7.8
CVE-2014-9904 [HIGH] linux vulnerabilities
linux vulnerabilities
It was discovered that the compression handling code in the Advanced Linux
Sound Architecture (ALSA) subsystem in the Linux kernel did not properly
check for an integer overflow. A local attacker could use this to cause a
denial of service (system crash). (CVE-2014-9904)
Kirill A. Shutemov discovered that memory manager in the Linux kernel did
not properly handle anonymous pages. A local attacker could use this to
cause a denial of service or possibly gain administrative privileges.
(CVE-2015-3288)
Vitaly Kuznetsov discovered that the Linux kernel did not properly suppress
hugetlbfs support in X86 paravirtualized guests. An attacker in the guest
OS could cause a denial of service (guest system crash). (CVE-2016-3961)
Ondrej Kozina discovered that the keyring inter
Kernel
Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security
kernel_security·2016-10-28·CVSS 6.2
CVE-2016-7042 [MEDIUM] Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security
Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security
Pull key fixes from James Morris:
- fix a buffer overflow when displaying /proc/keys [CVE-2016-7042].
- fix broken initialisation in the big_key implementation that can
result in an oops.
- make big_key depend on having a random number generator available in
Kconfig.
* 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security:
security/keys: make BIG_KEYS dependent on stdrng.
KEYS: Sort out big_key initialisation
KEYS: Fix short sprintf buffer in /proc/keys show function
Kernel
KEYS: Fix short sprintf buffer in /proc/keys show function
kernel_security·2016-10-26·CVSS 6.2
CVE-2016-7042 [MEDIUM] KEYS: Fix short sprintf buffer in /proc/keys show function
KEYS: Fix short sprintf buffer in /proc/keys show function
This fixes CVE-2016-7042.
Fix a short sprintf buffer in proc_keys_show(). If the gcc stack protector
is turned on, this can cause a panic due to stack corruption.
The problem is that xbuf[] is not big enough to hold a 64-bit timeout
rendered as weeks:
(gdb) p 0xffffffffffffffffULL/(60*60*24*7)
$2 = 30500568904943
That's 14 chars plus NUL, not 11 chars plus NUL.
Expand the buffer to 16 chars.
I think the unpatched code apparently works if the stack-protector is not
enabled because on a 32-bit machine the buffer won't be overflowed and on a
64-bit machine there's a 64-bit aligned pointer at one side and an int that
isn't checked again on the other side.
The panic incurred looks something like:
Kernel panic - not syncing: sta
OSV
CVE-2016-7042: The proc_keys_show function in security/keys/proc
osv·2016-10-16·CVSS 6.2
CVE-2016-7042 [MEDIUM] CVE-2016-7042: The proc_keys_show function in security/keys/proc
The proc_keys_show function in security/keys/proc.c in the Linux kernel through 4.8.2, when the GNU Compiler Collection (gcc) stack protector is enabled, uses an incorrect buffer size for certain timeout data, which allows local users to cause a denial of service (stack memory corruption and panic) by reading the /proc/keys file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-7042 kernel: Stack corruption while reading /proc/keys when gcc stack protector is enabled
bugzilla·2016-09-07·CVSS 6.2
CVE-2016-7042 [MEDIUM] CVE-2016-7042 kernel: Stack corruption while reading /proc/keys when gcc stack protector is enabled
CVE-2016-7042 kernel: Stack corruption while reading /proc/keys when gcc stack protector is enabled
It was found that when gcc stack protector is turned on, proc_keys_show() can cause a panic due to stack corruption. This happens because xbuf[] is not big enough to hold a 64-bit timeout rendered as weeks.
Product bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1373499
Discussion:
Acknowledgments:
Name: Ondrej Kozina (Red Hat)
---
Statement:
This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
Bugzilla
CVE-2016-7042 kernel: kernel panic due to stack corruption detected while reading /proc/keys after few operations with kernel keys [fedora-all]
bugzilla·2016-09-06·CVSS 6.2
CVE-2016-7042 [MEDIUM] CVE-2016-7042 kernel: kernel panic due to stack corruption detected while reading /proc/keys after few operations with kernel keys [fedora-all]
CVE-2016-7042 kernel: kernel panic due to stack corruption detected while reading /proc/keys after few operations with kernel keys [fedora-all]
Created attachment 1198213
reproducer
Description of problem:
I was testing new program using kernel keyring service when I was hit by following bug. After some time I managed to minimize the reproducer into quite simple one (attached as C source code).
I filled the security field but so far I'm not sure it's really security bug or not. I took better safe than sorry approach, I'm really not an expert here. Also the reproducer proves that if kernel stack protector is enabled any user with access to the system may kill it running the reproducer (due to stack protector steps in).
Version-Release number of selected component (if applicable):
kerne
http://rhn.redhat.com/errata/RHSA-2017-0817.htmlhttp://www.openwall.com/lists/oss-security/2016/10/13/5http://www.securityfocus.com/bid/93544https://access.redhat.com/errata/RHSA-2017:1842https://access.redhat.com/errata/RHSA-2017:2077https://access.redhat.com/errata/RHSA-2017:2669https://bugzilla.redhat.com/show_bug.cgi?id=1373966https://source.android.com/security/bulletin/2017-01-01.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0817.htmlhttp://www.openwall.com/lists/oss-security/2016/10/13/5http://www.securityfocus.com/bid/93544https://access.redhat.com/errata/RHSA-2017:1842https://access.redhat.com/errata/RHSA-2017:2077https://access.redhat.com/errata/RHSA-2017:2669https://bugzilla.redhat.com/show_bug.cgi?id=1373966https://source.android.com/security/bulletin/2017-01-01.html
2016-10-16
Published