Privilege escalation in Linux kernel - CVE-2019-9162
Published: February 28, 2019
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to array index error in SNMP NAT module (net/ipv4/netfilter/nf_nat_snmp_basic_main.c) when parsing ASN.1-encoded payloads in SNMP messages. A local user can set up new network namespaces that invoke iptables configuration and triggers SNMP translations, cause out-of-bounds read and write operations and execute arbitrary code on the system with elevated privileges.
Affected software
Fedora
kernel
kernel-headers
How to mitigate CVE-2019-9162
kernel - addressed in versions 4.20.12-100.fc28, 4.20.12-200.fc29, 4.20.13-100.fc28, 4.20.14-100.fc28
kernel-headers - addressed in versions 4.20.12-100.fc28, 4.20.12-200.fc29, 4.20.13-100.fc28, 4.20.14-100.fc28
External References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c4c07b4d6fa1f11880eab8e076d3d060ef3f55fc
- http://www.securityfocus.com/bid/107159
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1776
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.25
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.20.12
- https://github.com/torvalds/linux/commit/c4c07b4d6fa1f11880eab8e076d3d060ef3f55fc