漏洞信息详情
Linux kernel 权限许可和访问控制问题漏洞
漏洞简介
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。NFSv4 implementation是其中的一个分布式文件系统协议。
Linux kernel 4.10.6及之前的版本中的net/xfrm/xfrm_user.c文件的‘xfrm_replay_verify_len’函数存在权限许可和访问控制漏洞。本地攻击者可利用该漏洞获取root权限或造成拒绝服务(基于堆的越边界访问)。
漏洞公告
目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f843ee6dd019bcece3e74e76ad9df0155655d0df
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=677e806da4d916052585301785d847c3b3e6186a
参考网址
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2017:2930
来源:BID
链接:https://www.securityfocus.com/bid/97018
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2017:2931
来源:MISC
链接:https://twitter.com/thezdi/status/842126074435665920
来源:CONFIRM
链接:http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=677e806da4d916052585301785d847c3b3e6186a
来源:CONFIRM
链接:https://github.com/torvalds/linux/commit/677e806da4d916052585301785d847c3b3e6186a
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2017:2918
来源:CONFIRM
链接:https://github.com/torvalds/linux/commit/f843ee6dd019bcece3e74e76ad9df0155655d0df
来源:CONFIRM
链接:http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f843ee6dd019bcece3e74e76ad9df0155655d0df
来源:MISC
链接:https://blog.trendmicro.com/results-pwn2own-2017-day-one/
来源:MISC
链接:http://www.eweek.com/security/ubuntu-linux-falls-on-day-1-of-pwn2own-hacking-competition
来源:CONFIRM
链接:http://openwall.com/lists/oss-security/2017/03/29/2
来源:CONFIRM
链接:https://source.android.com/security/bulletin/2017-05-01
来源:SECTRACK
链接:http://www.securitytracker.com/id/1038166
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:4168
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:4164
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:4159
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:4154
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021101107
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.4608/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/155607/Red-Hat-Security-Advisory-2019-4159-01.html
来源:us-cert.cisa.gov
链接:https://us-cert.cisa.gov/ics/advisories/icsa-21-280-02
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3344
受影响实体
- Linux Linux_kernel:4.8<!--2000-1-1-->
补丁
- Linux kernel 权限许可和访问控制漏洞的修复措施<!--2017-3-23-->
还没有评论,来说两句吧...