Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 219089 - hardened-sources: grsecurity <2.1.11-2.6.24.5 RBAC security bypass (CVE-2008-1940)
Summary: hardened-sources: grsecurity <2.1.11-2.6.24.5 RBAC security bypass (CVE-2008-...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/29899/
Whiteboard: [hardened < 2.6.23-r10] [hardened >= ...
Keywords:
Depends on:
Blocks:
 
Reported: 2008-04-23 22:51 UTC by Robert Buchholz (RETIRED)
Modified: 2008-05-11 05:12 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
Fix backported to 2.6.23 (4500_grsec-user_transition-bypass-fix.patch,3.62 KB, patch)
2008-04-24 01:06 UTC, Gordon Malm (RETIRED)
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2008-04-23 22:51:20 UTC
Secunia:
A security issue has been reported in grsecurity, which can be exploited by malicious, local users to bypass certain security restrictions.

The security issue is caused due to an error in the RBAC system when enforcing the "user_transition_deny" and "user_transition_allow" rules. This can be exploited to bypass the affected rules in calls to "sys_setfsuid()" and "sys_setfsgid()".

The security issue is reported in versions prior to 2.1.11-2.6.24.5 (2008-04-21) and 2.1.11-2.4.36.2 (2008-04-21).
Comment 1 Gordon Malm (RETIRED) gentoo-dev 2008-04-24 01:06:13 UTC
Created attachment 150781 [details, diff]
Fix backported to 2.6.23

Status update:
The patch uploaded with this posting will be included in the upcoming 2.6.23-r10 release, already in testing.  

The upcoming hardened-sources-2.6.24-r1 RC already has the latest grsec-2.1.11-2.6.24.5-200804211829.patch containing this fix and is also in testing since 2008-04-21.

Both will be added to the tree soonish.
Comment 2 Gordon Malm (RETIRED) gentoo-dev 2008-04-30 12:09:52 UTC
hardened-sources releases 2.6.23-r10 and 2.6.24-r1 are in the tree with this fix.  Bug can be closed when 2.6.23-r10 goes stable on x86, amd64 and ppc.
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2008-05-03 19:49:14 UTC
Do you guys at hardened handle stabilization, or shall we add arches to the bug?
Comment 4 Gordon Malm (RETIRED) gentoo-dev 2008-05-11 05:12:41 UTC
hardened-sources-2.6.23-r11 is marked stable on x86, amd64 and ppc.  Closing bug.