Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 131427 - Kernel: vserver-sources: Multiple local privilege escalation vulnerabilities (CVE-2006-2110)
Summary: Kernel: vserver-sources: Multiple local privilege escalation vulnerabilities ...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: High major (vote)
Assignee: Gentoo Security
URL: http://www.paul.sladen.org/vserver/ar...
Whiteboard: [vserver >=2.0.0 <2.0.2] [vserver >=2...
Keywords:
Depends on:
Blocks:
 
Reported: 2006-04-27 04:27 UTC by Benedikt Böhm (RETIRED)
Modified: 2009-07-13 14:36 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Benedikt Böhm (RETIRED) gentoo-dev 2006-04-27 04:27:50 UTC
vserver-sources is prone to multiple local privilege escalation vulnerabilities.

Inside a Virtual Private Server the distinction between the root user and a normal user is lost with regard to the following (vserver specific) capabilites:

- VXC_SET_UTSNAME: Allow setdomainname(2) and sethostname(2)
- VXC_SET_RLIMIT: Allow setrlimit(2)
- VXC_SYSLOG: Allow syslog(2)
- VXC_SECURE_MOUNT: Allow secure mount(2)
- VXC_SECURE_REMOUNT: Allow secure remount
- VXC_BINARY_MOUNT: Allow binary/network mounts
- VXC_QUOTA_CTL: Allow quota ioctl

All versions in portage are currently affected.

We are still awaiting the proper fix from upstream, which should be available in the next 24 hours i guess.
Comment 1 Benedikt Böhm (RETIRED) gentoo-dev 2006-04-27 04:35:06 UTC
Jan R
Comment 2 Benedikt Böhm (RETIRED) gentoo-dev 2006-04-27 04:35:06 UTC
Jan Rêkorajski (baggins@pld-linux.org) on irc.oftc.net#vserver reported this issue
Comment 3 Stefan Cornelius (RETIRED) gentoo-dev 2006-04-27 05:07:15 UTC
CCing phreak as second maintainer, please provide fixed ebuids but commit only if the fix/new version is public, thanks.
Comment 4 Benedikt Böhm (RETIRED) gentoo-dev 2006-04-27 23:41:42 UTC
The fix was released upstream in 2.0.2_rc18/2.1.1_rc18 (~arch) which are now in portage, additionally i have bumped 2.0.1 (arch) to -r4 with the fix backported.

A more detailed description of the bug can be found at http://www.paul.sladen.org/vserver/archives/200604/0323.html
Comment 5 Thierry Carrez (RETIRED) gentoo-dev 2006-04-28 10:51:38 UTC
This is a kernel issue.
Comment 6 Benedikt Böhm (RETIRED) gentoo-dev 2006-05-01 23:59:08 UTC
is there anything preventing the GLSA to be issued?
Comment 7 Tim Yamin (RETIRED) gentoo-dev 2006-05-05 13:55:21 UTC
I see no problem with doing a GLSA for this one issue as it only affects one sourceset, if you so wish, but we haven't done Kernel GLSAs since 200408 :)
Comment 8 Benedikt Böhm (RETIRED) gentoo-dev 2006-05-06 00:19:27 UTC
oh, ok.. then the issue is fixed :)
Comment 9 Tim Yamin (RETIRED) gentoo-dev 2006-05-06 07:01:00 UTC
Fixed then :)