Security restrictions bypass in Linux kernel - CVE-2017-1000365,CVE-2017-7482

 

Security restrictions bypass in Linux kernel - CVE-2017-1000365,CVE-2017-7482

Published: June 29, 2017 / Updated: July 11, 2017


Vulnerability identifier: #VU7237
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-1000365,CVE-2017-7482
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to bypass security restrictions on the target system.

The weakness exists due to the failure to take the argument and environment strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size) into account when imposing a size restriction. A local attacker can bypass security limitation and perform unauthorized actions.

Successful exploitation of the vulnerability results in access to the system.

Affected software

Linux kernel
Amazon Linux AMI
SUSE Linux
Ubuntu
Slackware Linux
Fedora
Opensuse

MRG Realtime
kernel-rt (Red Hat package)
kernel
Juniper Junos Space

How to mitigate CVE-2017-1000365,CVE-2017-7482

Update to version 4.11.6.

kernel-rt (Red Hat package) - update to 3.10.0-693.46.1.rt56.639.el6rt
kernel - addressed in versions 4.11.6-100.fc24, 4.11.6-101.fc24, 4.11.6-200.fc25, 4.11.6-201.fc25, 4.11.6-300.fc26, 4.11.6-301.fc26
Juniper Junos Space - update to 20.3R1

External References

Related Security Bulletins