<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>140444</bug_id>
          
          <creation_ts>2006-07-14 23:40 0000</creation_ts>
          <short_desc>Kernel: Local privilege escalation (CVE-2006-3626)</short_desc>
          <delta_ts>2009-07-11 12:22:59 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Kernel</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.17.y.git;a=commit;h=4a7ac3ab06932949d3069c1811f6f2a310f656c4</bug_file_loc>
          <status_whiteboard>[linux &lt;2.6.16.25] [linux &gt;=2.6.17 &lt;2.6.17.5]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>dragonheart@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>agriffis@gentoo.org</cc>
    
    <cc>chrb@gentoo.org</cc>
    
    <cc>jesse@boldandbusted.com</cc>
    
    <cc>johnm@gentoo.org</cc>
    
    <cc>kang@gentoo.org</cc>
    
    <cc>kernel@gentoo.org</cc>
    
    <cc>kumba@gentoo.org</cc>
    
    <cc>marineam@gentoo.org</cc>
    
    <cc>phil@anyware-tech.com</cc>

      

      
          <long_desc isprivate="0">
            <who>dragonheart@gentoo.org</who>
            <bug_when>2006-07-14 23:40:42 0000</bug_when>
            <thetext>A Linux Kernel Exploit was posted to Full-Disclosure effecting the 2.6.x kernels.
The attached code exploits a root race in /proc, The exploit has been acknowledged and a patch is now available.

The exploit can be found: http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047913.html

A patch for this exploit can be found here: http://lkml.org/lkml/diff/2006/7/14/306/1

(written by _array on #gentoo-hardened)

Note: http://lkml.org/lkml/2006/7/15/5 says that &lt;HAL-0.5.7 may have troubles
latest gentoo stable is hal-0.5.5.1-r3 (all arches)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dragonheart@gentoo.org</who>
            <bug_when>2006-07-15 00:17:24 0000</bug_when>
            <thetext>CVE from http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.17.5</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>plasmaroo@gentoo.org</who>
            <bug_when>2006-07-15 05:44:44 0000</bug_when>
            <thetext>Please do *not* use the 2.6.16.25 or 2.6.17.5 fix; I&apos;m attaching a better one which shouldn&apos;t break HAL &amp; etc...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>plasmaroo@gentoo.org</who>
            <bug_when>2006-07-15 05:45:24 0000</bug_when>
            <thetext>Created an attachment (id=91781)
Patch

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>plasmaroo@gentoo.org</who>
            <bug_when>2006-07-15 07:08:26 0000</bug_when>
            <thetext>Maintainers please bump your genpatches (2.6.16-15 or 2.6.17-4) or use the attached patch (don&apos;t use 2.6.17.5):

ck-sources: marineam
hardened-sources-2.6: johnm, hardened
hppa-sources: GMSoft
mips-sources: `Kumba
rsbac-sources: kang
sh-sources: sh
suspend2-sources: brix
usermode-sources: dang
xbox-sources: chrb
xen-sources: chrb, agriffis</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dragonheart@gentoo.org</who>
            <bug_when>2006-07-15 07:10:33 0000</bug_when>
            <thetext>workaround for those waiting for a release is to mount proc with options nosuid as suggested by padde in #gentoo-bugs</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>phreak@gentoo.org</who>
            <bug_when>2006-07-15 07:24:28 0000</bug_when>
            <thetext>gentoo-sources-2.6.16/2.6.17 -&gt; done
suspend2-sources-2.6.16/2.6.17 -&gt; done
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>phreak@gentoo.org</who>
            <bug_when>2006-07-15 08:06:15 0000</bug_when>
            <thetext>openvz-sources-026.015 (2.6.16) -&gt; done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>phreak@gentoo.org</who>
            <bug_when>2006-07-15 08:34:28 0000</bug_when>
            <thetext>ck-sources-2.6.16/2.6.17 -&gt; done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2006-07-15 09:04:19 0000</bug_when>
            <thetext>hardened-sources-2.6.16-r11 bumped with genpatches 14</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dang@gentoo.org</who>
            <bug_when>2006-07-15 09:53:38 0000</bug_when>
            <thetext>usermode-sources bumped.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2006-07-15 10:53:14 0000</bug_when>
            <thetext>(In reply to comment #9)
I ment 15

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dsd@gentoo.org</who>
            <bug_when>2006-07-15 17:35:07 0000</bug_when>
            <thetext>*** Bug 140581 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>plasmaroo@gentoo.org</who>
            <bug_when>2006-07-17 09:11:50 0000</bug_when>
            <thetext>*** Bug 140797 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>langthang@gentoo.org</who>
            <bug_when>2006-07-17 10:05:01 0000</bug_when>
            <thetext>(In reply to comment #4)
&gt; Maintainers please bump your genpatches (2.6.16-15 or 2.6.17-4) or use the
&gt; attached patch (don&apos;t use 2.6.17.5):
&gt; 
&gt; ck-sources: marineam
&gt; hardened-sources-2.6: johnm, hardened
&gt; hppa-sources: GMSoft
&gt; mips-sources: `Kumba
&gt; rsbac-sources: kang
&gt; sh-sources: sh
&gt; suspend2-sources: brix
&gt; usermode-sources: dang
&gt; xbox-sources: chrb
&gt; xen-sources: chrb, agriffis
&gt; 

2.6.16.26 fix these issues right? If so I have copied xen-sources-2.6.16.18 to xen-sources-2.6.16.26 and and it WFM on my xen test box.

HTH.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>plasmaroo@gentoo.org</who>
            <bug_when>2006-07-17 13:24:11 0000</bug_when>
            <thetext>(In reply to comment #14)
&gt; 2.6.16.26 fix these issues right? If so I have copied xen-sources-2.6.16.18 to
&gt; xen-sources-2.6.16.26 and and it WFM on my xen test box.

Yes, .26 fixes these issues correctly.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gmsoft@gentoo.org</who>
            <bug_when>2006-07-18 13:04:20 0000</bug_when>
            <thetext>Fixed on hppa. First commit from my new place \o/</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>chrb@gentoo.org</who>
            <bug_when>2006-07-19 13:47:44 0000</bug_when>
            <thetext>I&apos;ve updated xen and xbox -sources to 2.6.16.26.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hlieberman@gentoo.org</who>
            <bug_when>2006-11-01 19:06:22 0000</bug_when>
            <thetext>SH, RSBAC, this one too. Bump or patch.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kang@gentoo.org</who>
            <bug_when>2006-11-09 06:40:26 0000</bug_when>
            <thetext>rsbac-sources bumped to 2.6.18 in ~</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hlieberman@gentoo.org</who>
            <bug_when>2006-11-09 18:26:55 0000</bug_when>
            <thetext>As discussed in the past, SH no longer is kept track of by Gentoo Kernel Security. Closing bug.</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>91781</attachid>
            <date>2006-07-15 05:45 0000</date>
            <desc>Patch</desc>
            <filename>1505_procfs-dumpable-race.patch</filename>
            <type>text/plain</type>
            <data encoding="base64">SW5kZXg6IGxpbnV4LTIuNi4xNi1nZW50b28tcjEyL2ZzL3Byb2MvYmFzZS5jCj09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0K
LS0tIGxpbnV4LTIuNi4xNi1nZW50b28tcjEyLm9yaWcvZnMvcHJvYy9iYXNlLmMKKysrIGxpbnV4
LTIuNi4xNi1nZW50b28tcjEyL2ZzL3Byb2MvYmFzZS5jCkBAIC0xMzY3LDYgKzEzNjcsNyBAQCBz
dGF0aWMgaW50IHBpZF9yZXZhbGlkYXRlKHN0cnVjdCBkZW50cnkgCiAJCQlpbm9kZS0+aV91aWQg
PSAwOwogCQkJaW5vZGUtPmlfZ2lkID0gMDsKIAkJfQorCQlpbm9kZS0+aV9tb2RlICY9IH4oU19J
U1VJRCB8IFNfSVNHSUQpOwogCQlzZWN1cml0eV90YXNrX3RvX2lub2RlKHRhc2ssIGlub2RlKTsK
IAkJcmV0dXJuIDE7CiAJfQpAQCAtMTM5NCw2ICsxMzk1LDcgQEAgc3RhdGljIGludCB0aWRfZmRf
cmV2YWxpZGF0ZShzdHJ1Y3QgZGVudAogCQkJCWlub2RlLT5pX3VpZCA9IDA7CiAJCQkJaW5vZGUt
PmlfZ2lkID0gMDsKIAkJCX0KKwkJCWlub2RlLT5pX21vZGUgJj0gfihTX0lTVUlEIHwgU19JU0dJ
RCk7CiAJCQlzZWN1cml0eV90YXNrX3RvX2lub2RlKHRhc2ssIGlub2RlKTsKIAkJCXJldHVybiAx
OwogCQl9Cg==
</data>        

          </attachment>
    </bug>

</bugzilla>