BugTraq
Linux kernel ELF core dump privilege elevation May 11 2005 11:08AM
Paul Starzetz (ihaquer isec pl) (4 replies)
Re: Linux kernel ELF core dump privilege elevation May 12 2005 01:46AM
antoine (antoine nagafix co uk) (1 replies)
Paul,

I failed to crash any of my test machines, x86_86 based systems get the
same result as reported by Bruno Lustosa (segfaults), x86 system exit
after printing ".. to crash" as do UML x86 systems. SELinux exits with:
"[+] phase 2, <RET> to crash Killed" but interestingly do not cause any
audit event.

I just stumbled upon another bug which does crash systems reliably, it
only works on x86_64 (maybe other 64 bit archs?). No CVE, and not sure
it can be used for privilege escalation, but it does crash hard:
"It is a kernel bug that allows to set non canonical addresses in 64bit
segment registers through ptrace." Andi Kleen on LKML.
It is being worked on. The (accidental) code that triggered it is
contained in a UML instance (kernel + filesystem and commands) - too big
and suboptimal to be published here and much smaller PoC code is doable.

Antoine

On Wed, 2005-05-11 at 13:08 +0200, Paul Starzetz wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> Hi,
>
> since it became clear from the discussion in January about the uselib()
> vulnerability, that the Linux community prefers full, non-embargoed
> disclosure of kernel bugs, I release full details right now. However to
> follows at least some of the responsable disclosure rules, no exploit code will be
> released. Instead, only a proof-of-concept code is released to demonstrate
> the vulnerability.
>
> regards
>
> - --
> Paul Starzetz
> iSEC Security Research
> http://isec.pl/
>
>
> Synopsis: Linux kernel ELF core dump privilege elevation
(...)

[ reply ]
Re: Linux kernel ELF core dump privilege elevation May 13 2005 10:10AM
Pedro Venda (pjvenda arrakis dhis org)
Re: Linux kernel ELF core dump privilege elevation (kernel module workaround) May 12 2005 12:29AM
Andrew Griffiths (andrewg felinemenace org) (1 replies)
Re: Linux kernel ELF core dump privilege elevation May 11 2005 07:34PM
Bruno Lustosa (bruno lists gmail com) (1 replies)
Re: Linux kernel ELF core dump privilege elevation May 12 2005 05:52PM
codeQ (newsclient teamq info)
Re: Linux kernel ELF core dump privilege elevation May 11 2005 06:12PM
Greg KH (gregkh suse de) (2 replies)
Re: Linux kernel ELF core dump privilege elevation May 11 2005 09:51PM
Paul Starzetz (ihaquer isec pl)
Re: Linux kernel ELF core dump privilege elevation May 11 2005 06:30PM
Greg KH (gregkh suse de)


 

Privacy Statement
Copyright 2010, SecurityFocus