Уязвимость обхода ограничений доступа в функции "sysrq_sysctl_handler" из файла "kernel/sysctl.c" ядра Linux, позволяющая изменять значение "dmesg_restrict" и читать кольцевой буфер ядра
Описание
Обнаружена уязвимость в функции sysrq_sysctl_handler из файла kernel/sysctl.c в ядре Linux до версии 2.6.39. Функция не требует наличия привилегии CAP_SYS_ADMIN для изменения значения dmesg_restrict. Это позволяет локальным пользователям обойти предполагаемые ограничения доступа и читать содержимое кольцевого буфера ядра (kernel ring buffer), используя права суперпользователя (root). Проблема была продемонстрирована в среде Linux Containers (LXC).
Заявление
Red Hat Enterprise Linux 4 находится на этапе Production 3 жизненного цикла поддержки (подробнее), поэтому исправление данной проблемы в будущих обновлениях не планируется. Возможное исправление может быть включено в будущие обновления ядра для Red Hat Enterprise Linux 5, 6 и Red Hat Enterprise MRG.
Затронутые версии ПО
- Ядро Linux до версии 2.6.39
Тип уязвимости
- Обход ограничений доступа
- Чтение чувствительной информации
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 4 | kernel | Affected | ||
| Red Hat Enterprise Linux 5 | kernel | Affected | ||
| Red Hat Enterprise MRG 2 | realtime-kernel | Affected | ||
| Red Hat Enterprise Linux 6 | kernel | Fixed | RHSA-2012:0481 | 17.04.2012 |
Показывать по
Дополнительная информация
Статус:
EPSS
1.5 Low
CVSS2
Связанные уязвимости
The sysrq_sysctl_handler function in kernel/sysctl.c in the Linux kernel before 2.6.39 does not require the CAP_SYS_ADMIN capability to modify the dmesg_restrict value, which allows local users to bypass intended access restrictions and read the kernel ring buffer by leveraging root privileges, as demonstrated by a root user in a Linux Containers (aka LXC) environment.
The sysrq_sysctl_handler function in kernel/sysctl.c in the Linux kernel before 2.6.39 does not require the CAP_SYS_ADMIN capability to modify the dmesg_restrict value, which allows local users to bypass intended access restrictions and read the kernel ring buffer by leveraging root privileges, as demonstrated by a root user in a Linux Containers (aka LXC) environment.
The sysrq_sysctl_handler function in kernel/sysctl.c in the Linux kern ...
The sysrq_sysctl_handler function in kernel/sysctl.c in the Linux kernel before 2.6.39 does not require the CAP_SYS_ADMIN capability to modify the dmesg_restrict value, which allows local users to bypass intended access restrictions and read the kernel ring buffer by leveraging root privileges, as demonstrated by a root user in a Linux Containers (aka LXC) environment.
EPSS
1.5 Low
CVSS2