Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 202778 - sys-kernel/*-sources <=2.6.23.X "mmap_min_addr" Local Security Bypass Vulnerability (CVE-2007-6434)
Summary: sys-kernel/*-sources <=2.6.23.X "mmap_min_addr" Local Security Bypass Vulnera...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.frsirt.com/english/advisor...
Whiteboard: [linux < 2.6.23.15][gp < 2.6.23-8]
Keywords:
Depends on:
Blocks:
 
Reported: 2007-12-19 13:33 UTC by Lars Hartmann
Modified: 2013-09-03 03:48 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Lars Hartmann 2007-12-19 13:33:44 UTC
Linux kernel 2.6.23 allows local users to create low pages in virtual userspace memory and bypass mmap_min_addr protection via a crafted executable file that calls the do_brk function.

Solution:
apply patch: http://groups.google.com/group/linux.kernel/browse_thread/thread/13bde11d06876040

Reproducible: Always
Comment 1 unnamedrambler 2008-03-21 20:09:09 UTC
[linux < 2.6.23.15] a0209f336a1dff0363b558a972eb71eef74e0084
also in 2.6.24 as ecaf18c15aac8bb9bed7b7aa0e382fe252e275d5 and 5a211a5deabcafdc764817d5b4510c767d317ddc ?


[gp < 2.6.23-8]