Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 150274 - sys-kernel/* registration weakness in linux kernel's binary formats
Summary: sys-kernel/* registration weakness in linux kernel's binary formats
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2006-10-06 06:46 UTC by Carsten Lohrke (RETIRED)
Modified: 2006-10-07 21:30 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Carsten Lohrke (RETIRED) gentoo-dev 2006-10-06 06:46:48 UTC
SHELLCODE Security Research <GoodFellas@shellcode.com.ar>

sent the following to full disclosure


--


Hello,
The present document aims to demonstrate a design weakness found in the
handling of simply 
linked   lists   used   to   register   binary   formats   handled   by
Linux   kernel,   and   affects   all   the   kernel 
families (2.0/2.2/2.4/2.6), allowing the insertion of infection modules
in kernel
Comment 1 Carsten Lohrke (RETIRED) gentoo-dev 2006-10-06 06:46:48 UTC
SHELLCODE Security Research <GoodFellas@shellcode.com.ar>

sent the following to full disclosure


--


Hello,
The present document aims to demonstrate a design weakness found in the
handling of simply 
linked   lists   used   to   register   binary   formats   handled   by
Linux   kernel,   and   affects   all   the   kernel 
families (2.0/2.2/2.4/2.6), allowing the insertion of infection modules
in kernel­ space that can be 
used by malicious users to create infection tools, for example rootkits.

POC, details and proposed solution at:
English version: http://www.shellcode.com.ar/docz/binfmt-en.pdf
Spanish version: http://www.shellcode.com.ar/docz/binfmt-es.pdf

regards,
--
SHELLCODE Security Research TEAM
GoodFellas@shellcode.com.ar
http://www.shellcode.com.ar


--


I'm looking through the last weeks vulnerability reports atm., if we have missed one. I did not examine the paper, but it looks good enough to let some kernel guy have a look (and possibly dismiss it).
Comment 2 SpanKY gentoo-dev 2006-10-06 09:16:54 UTC
the paper is just fucking stupid ... the guys who wrote it need to be shot
Comment 3 rd 2006-10-07 21:30:00 UTC
this is a feature, not a bug