<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>86638</bug_id>
          
          <creation_ts>2005-03-25 04:25 0000</creation_ts>
          <short_desc>af_bluetooth local root exploit (CAN-2005-0750)</short_desc>
          <delta_ts>2009-05-03 15:05:19 0000</delta_ts>
          
          
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Kernel</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>[linux &lt; 2.4.30][ linux &gt;= 2.6 &lt; 2.6.11.6]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaervosz@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>kang@gentoo.org</cc>
    
    <cc>kern-sec@gentoo.org</cc>
    
    <cc>rajiv@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-03-25 04:25:05 0000</bug_when>
            <thetext>there is a local root exploit by integer underflow in the bluetooth handling,
triggerable by any user if you have bluetooth modules installed.

(I think using socket(AF_BLUETOOTH, -index, x); )

Marcel has posted below patch, I am not sure which bk tree that is it is
however.

CAN-2005-0750 as by Mark J Cox.

An actual exploit supposedly exist already.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-03-25 04:25:50 0000</bug_when>
            <thetext>Created an attachment (id=54428)
CAN-2005-0750.patch
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-03-26 09:07:03 0000</bug_when>
            <thetext>Patch posted in BK tree. New kernel release should follow.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-03-26 09:18:04 0000</bug_when>
            <thetext>Fixed in vanilla 2.6.11.6
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.6</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kumba@gentoo.org</who>
            <bug_when>2005-04-23 22:28:18 0000</bug_when>
            <thetext>mips-sources fixed.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dsd@gentoo.org</who>
            <bug_when>2005-04-27 13:43:23 0000</bug_when>
            <thetext>Fixed in gentoo-sources-2.6.11-r6</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>r2d2@gentoo.org</who>
            <bug_when>2005-05-17 16:34:00 0000</bug_when>
            <thetext>Another that can probably be closed now.
http://kiss.gentoo.org/dev/viewBug.php?BugID=86638</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-05-23 04:56:47 0000</bug_when>
            <thetext>*** Bug 87901 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-05-23 04:59:04 0000</bug_when>
            <thetext>This also affects the 2.4 series.

From solar :
grsec-sources-2.4.30 is in the tree as ~arch.

Note for other bumpers of 2.4.x series.
CAN-2004-1056.patch and linux-2.4.28-random-poolsize.patch have never 
been applied to mainline.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>plasmaroo@gentoo.org</who>
            <bug_when>2005-08-20 11:22:34 0000</bug_when>
            <thetext>rsbac-sources affected.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>plasmaroo@gentoo.org</who>
            <bug_when>2005-11-26 02:34:57 0000</bug_when>
            <thetext>All fixed, closing.</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>54428</attachid>
            <date>2005-03-25 04:25 0000</date>
            <desc>CAN-2005-0750.patch</desc>
            <filename>CAN-2005-0750.patch</filename>
            <type>text/plain</type>
            <data encoding="base64">PT09PT0gbmV0L2JsdWV0b290aC9hZl9ibHVldG9vdGguYyAxLjQwIHZzIGVkaXRlZCA9PT09PQot
LS0gMS40MC9uZXQvYmx1ZXRvb3RoL2FmX2JsdWV0b290aC5jCTIwMDUtMDMtMTggMTU6MDc6MjIg
KzAxOjAwCisrKyBlZGl0ZWQvbmV0L2JsdWV0b290aC9hZl9ibHVldG9vdGguYwkyMDA1LTAzLTI0
IDE5OjQyOjE2ICswMTowMApAQCAtNjIsNyArNjIsNyBAQAogCiBpbnQgYnRfc29ja19yZWdpc3Rl
cihpbnQgcHJvdG8sIHN0cnVjdCBuZXRfcHJvdG9fZmFtaWx5ICpvcHMpCiB7Ci0JaWYgKHByb3Rv
ID49IEJUX01BWF9QUk9UTykKKwlpZiAocHJvdG8gPCAwIHx8IHByb3RvID49IEJUX01BWF9QUk9U
TykKIAkJcmV0dXJuIC1FSU5WQUw7CiAKIAlpZiAoYnRfcHJvdG9bcHJvdG9dKQpAQCAtNzUsNyAr
NzUsNyBAQAogCiBpbnQgYnRfc29ja191bnJlZ2lzdGVyKGludCBwcm90bykKIHsKLQlpZiAocHJv
dG8gPj0gQlRfTUFYX1BST1RPKQorCWlmIChwcm90byA8IDAgfHwgcHJvdG8gPj0gQlRfTUFYX1BS
T1RPKQogCQlyZXR1cm4gLUVJTlZBTDsKIAogCWlmICghYnRfcHJvdG9bcHJvdG9dKQpAQCAtOTAs
NyArOTAsNyBAQAogewogCWludCBlcnIgPSAwOwogCi0JaWYgKHByb3RvID49IEJUX01BWF9QUk9U
TykKKwlpZiAocHJvdG8gPCAwIHx8IHByb3RvID49IEJUX01BWF9QUk9UTykKIAkJcmV0dXJuIC1F
SU5WQUw7CiAKICNpZiBkZWZpbmVkKENPTkZJR19LTU9EKQo=
</data>        

          </attachment>
    </bug>

</bugzilla>