CVE-2017-1000365
published 2017-06-19CVE-2017-1000365: The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), but does…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.90%
56.1th percentile
The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), but does not take the argument and environment pointers into account, which allows attackers to bypass this limitation. This affects Linux Kernel versions 4.11.5 and earlier. It appears that this feature was introduced in the Linux Kernel version 2.6.23.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.11.11-1 (bookworm) | linux 4.11.11-1 (bookworm) |
| linux | linux_kernel | >= 0 < 4.11.11-1 | 4.11.11-1 |
| linux | linux_kernel | >= 0 < 4.11.11-1 | 4.11.11-1 |
| linux | linux_kernel | >= 0 < 4.11.11-1 | 4.11.11-1 |
| linux | linux_kernel | >= 0 < 4.11.11-1 | 4.11.11-1 |
| linux | linux_kernel | >= 0 < 3.13.0-126.175 | 3.13.0-126.175 |
| linux | linux_kernel | >= 0 < 4.4.0-92.115 | 4.4.0-92.115 |
| linux | linux_kernel | >= 0 < 4.4.0-89.112 | 4.4.0-89.112 |
| linux | linux_kernel | >= 2.6.23 < 3.2.91 | 3.2.91 |
| linux | linux_kernel | >= 3.11 < 3.16.46 | 3.16.46 |
| linux | linux_kernel | >= 3.17 < 3.18.59 | 3.18.59 |
| linux | linux_kernel | >= 3.19 < 4.1.43 | 4.1.43 |
| linux | linux_kernel | >= 3.3 < 3.10.108 | 3.10.108 |
| linux | linux_kernel | >= 4.1 < 4.1.43 | 4.1.43 |
| linux | linux_kernel | >= 4.10 < 4.11.12 | 4.11.12 |
| linux | linux_kernel | >= 4.10 < 4.11.8 | 4.11.8 |
| linux | linux_kernel | >= 4.12 < 4.12.3 | 4.12.3 |
| linux | linux_kernel | >= 4.2 < 4.4.78 | 4.4.78 |
| linux | linux_kernel | >= 4.2 < 4.4.75 | 4.4.75 |
| linux | linux_kernel | >= 4.5 < 4.9.39 | 4.9.39 |
| linux | linux_kernel | >= 4.5 < 4.9.35 | 4.9.35 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Xenial HWE) regression
vendor_ubuntu·2017-08-16·CVSS 7.8
[HIGH] Linux kernel (Xenial HWE) regression
Title: Linux kernel (Xenial HWE) regression
Summary: USN-3378-2 introduced a regression the Linux Hardware Enablement
kernel.
USN-3392-1 fixed a regression in the Linux kernel for Ubuntu 16.04 LTS.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu 14.04 LTS.
USN-3378-2 fixed vulnerabilities in the Linux Hardware Enablement
kernel. Unfortunately, a regression was introduced that prevented
conntrack from working correctly in some situations. This update
fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a
Ubuntu
Linux kernel regression
vendor_ubuntu·2017-08-16·CVSS 7.8
[HIGH] Linux kernel regression
Title: Linux kernel regression
Summary: USN-3378-1 introduced a regression in the Linux kernel.
USN-3378-1 fixed vulnerabilities in the Linux kernel. Unfortunately, a
regression was introduced that prevented conntrack from working
correctly in some situations. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbi
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2017-08-07·CVSS 4.7
CVE-2016-8405 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3381-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.
Peter Pi discovered that the colormap handling for frame buffer devices in
the Linux kernel contained an integer overflow. A local attacker could use
this to disclose sensitive information (kernel memory). (CVE-2016-8405)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
It was discovered that SELinux i
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-08-07·CVSS 4.7
CVE-2016-8405 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Peter Pi discovered that the colormap handling for frame buffer devices in
the Linux kernel contained an integer overflow. A local attacker could use
this to disclose sensitive information (kernel memory). (CVE-2016-8405)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
It was discovered that SELinux in the Linux kernel did not properly handle
empty writes to /proc/pid/attr. A local attacker could use this to cause a
denial of service (system crash). (CVE-2017-2618)
石磊 discovered that the RxRPC Kerberos 5 ticket handling co
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2017-08-03·CVSS 7.8
CVE-2017-1000365 [HIGH] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3377-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.04.
This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 17.04 for Ubuntu
16.04 LTS.
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
李强 discovered
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-08-03·CVSS 7.8
CVE-2017-1000365 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
李强 discovered that the Virtio GPU driver in the Linux kernel did not
properly free memory in some situations. A local attacker could use this to
cause a denial of service (memory consumption). (CVE-2017-10810)
石磊 discovered
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2017-08-03·CVSS 7.8
CVE-2017-1000365 [HIGH] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3378-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
Red Hat
kernel: offset2lib allows for the stack guard page to be jumped over
vendor_redhat·2017-06-19·CVSS 7.8
CVE-2017-1000371 [HIGH] CWE-20 kernel: offset2lib allows for the stack guard page to be jumped over
kernel: offset2lib allows for the stack guard page to be jumped over
The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1 Gigabyte of memory is allocated (the maximum under the 1/4 restriction) then the stack will be grown down to 0x80000000, and as the PIE binary is mapped above 0x80000000 the minimum distance between the end of the PIE binary's read-write segment and the start of the stack becomes small enough that the stack guard page can be jumped over by an attacker. This affects Linux Kernel version 4.11.5. This is a different issue than CVE-2017-1000370 and CVE-2017-1000365. This issue appears to be limited to i386 based systems.
A flaw was found in the Linux kernel's implementation of mapping ELF PIE binary loadi
Red Hat
kernel: RLIMIT_STACK/RLIMIT_INFINITY string size limitation bypass
vendor_redhat·2017-06-19·CVSS 7.8
CVE-2017-1000365 [HIGH] CWE-20 kernel: RLIMIT_STACK/RLIMIT_INFINITY string size limitation bypass
kernel: RLIMIT_STACK/RLIMIT_INFINITY string size limitation bypass
The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), but does not take the argument and environment pointers into account, which allows attackers to bypass this limitation. This affects Linux Kernel versions 4.11.5 and earlier. It appears that this feature was introduced in the Linux Kernel version 2.6.23.
The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIMIT_INFINITY, but does not take the argument and environment pointers into account, which allows attackers to bypass this limitation.
Statement: This issue affects the Linux kernel packages as shipped with Red
Debian
CVE-2017-1000371: linux - The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RL...
vendor_debian·2017·CVSS 7.8
CVE-2017-1000371 [HIGH] CVE-2017-1000371: linux - The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RL...
The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1 Gigabyte of memory is allocated (the maximum under the 1/4 restriction) then the stack will be grown down to 0x80000000, and as the PIE binary is mapped above 0x80000000 the minimum distance between the end of the PIE binary's read-write segment and the start of the stack becomes small enough that the stack guard page can be jumped over by an attacker. This affects Linux Kernel version 4.11.5. This is a different issue than CVE-2017-1000370 and CVE-2017-1000365. This issue appears to be limited to i386 based systems.
Scope: local
bookworm: resolved (fixed in 4.11.11-1)
bullseye: resolved (fixed in 4.11.11-1)
forky: resolved (fixed in 4.11.11-1)
sid: resolved (fixed in 4.
Debian
CVE-2017-1000365: linux - The Linux Kernel imposes a size restriction on the arguments and environmental s...
vendor_debian·2017·CVSS 7.8
CVE-2017-1000365 [HIGH] CVE-2017-1000365: linux - The Linux Kernel imposes a size restriction on the arguments and environmental s...
The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), but does not take the argument and environment pointers into account, which allows attackers to bypass this limitation. This affects Linux Kernel versions 4.11.5 and earlier. It appears that this feature was introduced in the Linux Kernel version 2.6.23.
Scope: local
bookworm: resolved (fixed in 4.11.11-1)
bullseye: resolved (fixed in 4.11.11-1)
forky: resolved (fixed in 4.11.11-1)
sid: resolved (fixed in 4.11.11-1)
trixie: resolved (fixed in 4.11.11-1)
GHSA
GHSA-32r2-rwm4-hqgg: The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), bu
ghsa_unreviewed·2022-05-13
CVE-2017-1000365 [HIGH] GHSA-32r2-rwm4-hqgg: The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), bu
The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), but does not take the argument and environment pointers into account, which allows attackers to bypass this limitation. This affects Linux Kernel versions 4.11.5 and earlier. It appears that this feature was introduced in the Linux Kernel version 2.6.23.
GHSA
GHSA-wr3q-fcxj-4873: The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1 Gigabyte of memory is allocat
ghsa_unreviewed·2022-05-13·CVSS 7.8
CVE-2017-1000371 [HIGH] GHSA-wr3q-fcxj-4873: The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1 Gigabyte of memory is allocat
The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1 Gigabyte of memory is allocated (the maximum under the 1/4 restriction) then the stack will be grown down to 0x80000000, and as the PIE binary is mapped above 0x80000000 the minimum distance between the end of the PIE binary's read-write segment and the start of the stack becomes small enough that the stack guard page can be jumped over by an attacker. This affects Linux Kernel version 4.11.5. This is a different issue than CVE-2017-1000370 and CVE-2017-1000365. This issue appears to be limited to i386 based systems.
OSV
linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon regression
osv·2017-08-16·CVSS 7.8
[HIGH] linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon regression
linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon regression
USN-3378-1 fixed vulnerabilities in the Linux kernel. Unfortunately, a
regression was introduced that prevented conntrack from working
correctly in some situations. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000
OSV
linux-lts-xenial regression
osv·2017-08-16·CVSS 7.8
[HIGH] linux-lts-xenial regression
linux-lts-xenial regression
USN-3392-1 fixed a regression in the Linux kernel for Ubuntu 16.04 LTS.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu 14.04 LTS.
USN-3378-2 fixed vulnerabilities in the Linux Hardware Enablement
kernel. Unfortunately, a regression was introduced that prevented
conntrack from working correctly in some situations. This update
fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered tha
OSV
linux vulnerabilities
osv·2017-08-07·CVSS 4.7
CVE-2016-8405 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Peter Pi discovered that the colormap handling for frame buffer devices in
the Linux kernel contained an integer overflow. A local attacker could use
this to disclose sensitive information (kernel memory). (CVE-2016-8405)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
It was discovered that SELinux in the Linux kernel did not properly handle
empty writes to /proc/pid/attr. A local attacker could use this to cause a
denial of service (system crash). (CVE-2017-2618)
石磊 discovered that the RxRPC Kerberos 5 ticket handling code in the
Linux kernel did not properly verify metadata. A remote attacker could
OSV
linux-hwe vulnerabilities
osv·2017-08-03·CVSS 7.8
CVE-2017-7533 [HIGH] linux-hwe vulnerabilities
linux-hwe vulnerabilities
USN-3377-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.04.
This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 17.04 for Ubuntu
16.04 LTS.
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
李强 discovered that the Virtio GPU driver in the Linux kernel did not
properly free memory in so
OSV
linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities
osv·2017-08-03·CVSS 7.8
CVE-2017-7533 [HIGH] linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
李强 discovered that the Virtio GPU driver in the Linux kernel did not
properly free memory in some situations. A local attacker could use this to
cause a denial of service (memory consumption). (CVE-2017-10810)
石磊 discovered that the RxRPC Kerberos 5
OSV
linux-lts-xenial vulnerabilities
osv·2017-08-03·CVSS 7.8
[HIGH] linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
USN-3378-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
李强 discovered that the Virtio GPU driver in the Linux kernel did not
properly fr
Kernel
fs/exec.c: account for argv/envp pointers
kernel_security·2017-06-23·CVSS 7.8
CVE-2017-1000365 [HIGH] fs/exec.c: account for argv/envp pointers
fs/exec.c: account for argv/envp pointers
When limiting the argv/envp strings during exec to 1/4 of the stack limit,
the storage of the pointers to the strings was not included. This means
that an exec with huge numbers of tiny strings could eat 1/4 of the stack
limit in strings and then additional space would be later used by the
pointers to the strings.
For example, on 32-bit with a 8MB stack rlimit, an exec with 1677721
single-byte strings would consume less than 2MB of stack, the max (8MB /
4) amount allowed, but the pointers to the strings would consume the
remaining additional stack space (1677721 * 4 == 6710884).
The result (1677721 + 6710884 == 8388605) would exhaust stack space
entirely. Controlling this stack exhaustion could result in
pathological behavior in setuid binaries
OSV
CVE-2017-1000365: The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), bu
osv·2017-06-19·CVSS 7.8
CVE-2017-1000365 [HIGH] CVE-2017-1000365: The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), bu
The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), but does not take the argument and environment pointers into account, which allows attackers to bypass this limitation. This affects Linux Kernel versions 4.11.5 and earlier. It appears that this feature was introduced in the Linux Kernel version 2.6.23.
OSV
CVE-2017-1000371: The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1 Gigabyte of memory is allocat
osv·2017-06-19·CVSS 7.8
CVE-2017-1000371 [HIGH] CVE-2017-1000371: The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1 Gigabyte of memory is allocat
The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1 Gigabyte of memory is allocated (the maximum under the 1/4 restriction) then the stack will be grown down to 0x80000000, and as the PIE binary is mapped above 0x80000000 the minimum distance between the end of the PIE binary's read-write segment and the start of the stack becomes small enough that the stack guard page can be jumped over by an attacker. This affects Linux Kernel version 4.11.5. This is a different issue than CVE-2017-1000370 and CVE-2017-1000365. This issue appears to be limited to i386 based systems.
No detection rules found.
No public exploits indexed.
Qualys
The Stack Clash | Qualys
blogs_qualys·2017-06-19
The Stack Clash | Qualys
#### Table of Contents
- What is the Stack Clash?
- What is the Stack Clash vulnerability, precisely?
- Why is it called the Stack Clash?
- Is it a new vulnerability?
- Is the Stack Clash one or several vulnerabilities?
- Am I affected by the Stack Clash?
- What are the risks posed by the Stack Clash?
- Is it exploitable remotely?
- How can I protect my system from the Stack Clash?
- What if I cant (or dont want to) update or reboot my system?
- Where can I find the Stack Clash exploits?
- Where can I get more information?
- I want to write my own Stack Clash exploit, where do I start?
- Is the Sudo vulnerability Qualys published on May 30 related to Stack Clash?
## What is the Stack Clash?
The Stack Clash is a vulnerability in the memory management of several operating systems. It affe
Qualys
The Stack Clash
blogs_qualys·2017-06-19
The Stack Clash
## Table of Contents
What is the Stack Clash?
What is the Stack Clash vulnerability, precisely?
Why is it called the Stack Clash?
Is it a new vulnerability?
Is the Stack Clash one or several vulnerabilities?
Am I affected by the Stack Clash?
What are the risks posed by the Stack Clash?
Is it exploitable remotely?
How can I protect my system from the Stack Clash?
What if I cant (or dont want to) update or reboot my system?
Where can I find the Stack Clash exploits?
Where can I get more information?
I want to write my own Stack Clash exploit, where do I start?
Is the Sudo vulnerability Qualys published on May 30 related to Stack Clash?
## What is the Stack Clash?
The Stack Clash is a vulnerability in the memory management of several operating systems. It affects Linux, OpenBS
Bugzilla
CVE-2017-1000365 kernel: RLIMIT_STACK/RLIMIT_INFINITY string size limitation bypass [fedora-all]
bugzilla·2017-06-19·CVSS 7.8
CVE-2017-1000365 [HIGH] CVE-2017-1000365 kernel: RLIMIT_STACK/RLIMIT_INFINITY string size limitation bypass [fedora-all]
CVE-2017-1000365 kernel: RLIMIT_STACK/RLIMIT_INFINITY string size limitation bypass [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2017-1000365 kernel: RLIMIT_STACK/RLIMIT_INFINITY string size limitation bypass
bugzilla·2017-06-16·CVSS 7.8
CVE-2017-1000365 [HIGH] CVE-2017-1000365 kernel: RLIMIT_STACK/RLIMIT_INFINITY string size limitation bypass
CVE-2017-1000365 kernel: RLIMIT_STACK/RLIMIT_INFINITY string size limitation bypass
The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIMIT_INFINITY (1/4 of the size), but does not take the argument and environment pointers into account, which allows attackers to bypass this limitation.
This method in itself is not an exploit, but bypassing this mechanism is the flaw/issue being tracked.
Upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=98da7d08850fb8bdeb395d6368ed15753304aa0c
Discussion:
Acknowledgments:
Name: Qualys Inc.
---
External References:
https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt
---
Created kernel tracking bugs for this issue:
Affects: fedo
Bugzilla
CVE-2017-1000371 kernel: offset2lib allows for the stack guard page to be jumped over
bugzilla·2017-06-16·CVSS 7.8
CVE-2017-1000371 [HIGH] CVE-2017-1000371 kernel: offset2lib allows for the stack guard page to be jumped over
CVE-2017-1000371 kernel: offset2lib allows for the stack guard page to be jumped over
The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1 Gigabyte of memory is allocated (the maximum under the 1/4 restriction) then the stack will be grown down to 0x80000000, and as the PIE binary is mapped above 0x80000000 the minimum distance between the end of the PIE binary's read-write segment and the start of the stack becomes small enough that the stack guard page can be jumped over by an attacker. This affects Linux Kernel version 4.11.5. This is a different issue than CVE-2017-1000370 and CVE-2017-1000365. This issue appears to be limited to i386 based systems.
Upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/to
http://www.debian.org/security/2017/dsa-3927http://www.debian.org/security/2017/dsa-3945http://www.securityfocus.com/bid/99156https://access.redhat.com/security/cve/CVE-2017-1000365https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txthttp://www.debian.org/security/2017/dsa-3927http://www.debian.org/security/2017/dsa-3945http://www.securityfocus.com/bid/99156https://access.redhat.com/security/cve/CVE-2017-1000365https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt
2017-06-19
Published