Security restrictions bypass in Linux kernel - CVE-2017-1000365,CVE-2017-7482
Published: June 29, 2017 / Updated: July 11, 2017
Vulnerability identifier: #VU7237
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-1000365,CVE-2017-7482
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to bypass security restrictions on the target system.
The weakness exists due to the failure to take the argument and environment strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size) into account when imposing a size restriction. A local attacker can bypass security limitation and perform unauthorized actions.
Successful exploitation of the vulnerability results in access to the system.
The weakness exists due to the failure to take the argument and environment strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size) into account when imposing a size restriction. A local attacker can bypass security limitation and perform unauthorized actions.
Successful exploitation of the vulnerability results in access to the system.
Affected software
Linux kernel
Amazon Linux AMI
SUSE Linux
Ubuntu
Slackware Linux
Fedora
Opensuse
MRG Realtime
kernel-rt (Red Hat package)
kernel
Juniper Junos Space
Amazon Linux AMI
SUSE Linux
Ubuntu
Slackware Linux
Fedora
Opensuse
MRG Realtime
kernel-rt (Red Hat package)
kernel
Juniper Junos Space
How to mitigate CVE-2017-1000365,CVE-2017-7482
Update to version 4.11.6.
kernel-rt (Red Hat package) - update to 3.10.0-693.46.1.rt56.639.el6rt
kernel - addressed in versions 4.11.6-100.fc24, 4.11.6-101.fc24, 4.11.6-200.fc25, 4.11.6-201.fc25, 4.11.6-300.fc26, 4.11.6-301.fc26
Juniper Junos Space - update to 20.3R1
kernel - addressed in versions 4.11.6-100.fc24, 4.11.6-101.fc24, 4.11.6-200.fc25, 4.11.6-201.fc25, 4.11.6-300.fc26, 4.11.6-301.fc26
Juniper Junos Space - update to 20.3R1
External References
Related Security Bulletins
- Slackware Linux update for kernel
- Slackware Linux 14.1 update for kernel
- Slackware Linux update for kernel
- openSUSE update for the Linux Kernel
- Security restrictions bypass in Linux Kernel
- Ubuntu update for Linux kernel
- Ubuntu update for Linux kernel (Trusty HWE)
- Red Hat update for kernel-rt
- SUSE Linux update for the Linux Kernel
- Amazon Linux AMI update for kernel
- Multiple vulnerabilities in Juniper Junos Space
- Fedora 26 update for kernel
- Fedora 25 update for kernel
- Fedora 24 update for kernel
- Fedora 26 update for kernel
- Fedora 25 update for kernel
- Fedora 24 update for kernel