Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-13662

Опубликовано: 11 дек. 2016
Источник: fstec
CVSS3: 6.4
CVSS2: 5.9
EPSS Низкий

Описание

Уязвимость функции l2tp_eth_create() модуля net/l2tp/l2tp_eth.c реализации протокола L2TP операционной системы Linux связана с повторным использованием ранее освобожденной памяти. Эксплуатация уязвимости может позволить нарушителю повысить свои привилегии

Вендор

Canonical Ltd.
Google Inc
Сообщество свободного программного обеспечения

Наименование ПО

Ubuntu
Android
Debian GNU/Linux
Linux

Версия ПО

14.04 LTS (Ubuntu)
16.04 LTS (Ubuntu)
- (Android)
9 (Debian GNU/Linux)
18.04 LTS (Ubuntu)
10 (Debian GNU/Linux)
11 (Debian GNU/Linux)
12 (Debian GNU/Linux)
от 4.5 до 4.9.224 включительно (Linux)
13 (Debian GNU/Linux)
от 2.6.35 до 4.4.224 включительно (Linux)
от 4.11 до 4.12 (Linux)
от 4.14 до 4.14.181 включительно (Linux)

Тип ПО

Операционная система

Операционные системы и аппаратные платформы

Canonical Ltd. Ubuntu 14.04 LTS
Canonical Ltd. Ubuntu 16.04 LTS
Google Inc Android -
Сообщество свободного программного обеспечения Debian GNU/Linux 9
Canonical Ltd. Ubuntu 18.04 LTS
Сообщество свободного программного обеспечения Debian GNU/Linux 10
Сообщество свободного программного обеспечения Debian GNU/Linux 11
Сообщество свободного программного обеспечения Debian GNU/Linux 12
Сообщество свободного программного обеспечения Linux от 4.5 до 4.9.224 включительно
Сообщество свободного программного обеспечения Debian GNU/Linux 13
Сообщество свободного программного обеспечения Linux от 2.6.35 до 4.4.224 включительно
Сообщество свободного программного обеспечения Linux от 4.11 до 4.12
Сообщество свободного программного обеспечения Linux от 4.14 до 4.14.181 включительно

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 5,9)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 6,4)

Возможные меры по устранению уязвимости

В условиях отсутствия обновлений безопасности от производителя рекомендуется придерживаться "Рекомендаций по безопасной настройке операционных систем LINUX", изложенных в методическом документе ФСТЭК России, утверждённом 25 декабря 2022 года.
Использование рекомендаций:
Для Android:
https://source.android.com/security/bulletin/pixel/2020-12-01
Для Linux:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=9ee369a405c57613d7c83a3967780c3e30c52ecc
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=54652eb12c1b72e9602d09cb2821d5760939190f
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=bb0a32ce4389e17e47e198d2cddaf141561581ad
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8c0e421525c9eb50d68e8f633f703ca31680b746
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4e4b21da3acc68a7ea55f850cacc13706b7480e9
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=e702c1204eb57788ef189c839c8c779368267d70
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f3c66d4e144a0904ea9b95d23ed9f8eb38c11bfb
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f026bc29a8e093edfbb2a77700454b285c97e8ad
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3953ae7b218df4d1e544b98a393666f9ae58a78c
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ee28de6bbd78c2e18111a0aef43ea746f28d2073
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f98be6c6359e7e4a61aaefb9964c1db31cb9ec0c
Для Debian GNU/Linux:
https://security-tracker.debian.org/tracker/CVE-2020-27067
https://deb.freexian.com/extended-lts/tracker/CVE-2020-27067
Для Ubuntu:
https://ubuntu.com/security/CVE-2020-27067

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Ссылки на источники

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 4%
0.00141
Низкий

6.4 Medium

CVSS3

5.9 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.4
ubuntu
почти 6 лет назад

In the l2tp subsystem, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-152409173

CVSS3: 6.4
redhat
больше 5 лет назад

In the l2tp subsystem, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-152409173

CVSS3: 6.4
nvd
почти 6 лет назад

In the l2tp subsystem, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-152409173

CVSS3: 6.4
debian
почти 6 лет назад

In the l2tp subsystem, there is a possible use after free due to a rac ...

github
больше 4 лет назад

In the l2tp subsystem, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-152409173

EPSS

Процентиль: 4%
0.00141
Низкий

6.4 Medium

CVSS3

5.9 Medium

CVSS2