Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-4080

Опубликовано: 23 мар. 2011
Источник: redhat
CVSS2: 1.5
EPSS Низкий

Уязвимость обхода ограничений доступа в функции "sysrq_sysctl_handler" из файла "kernel/sysctl.c" ядра Linux, позволяющая изменять значение "dmesg_restrict" и читать кольцевой буфер ядра

Описание

Обнаружена уязвимость в функции sysrq_sysctl_handler из файла kernel/sysctl.c в ядре Linux до версии 2.6.39. Функция не требует наличия привилегии CAP_SYS_ADMIN для изменения значения dmesg_restrict. Это позволяет локальным пользователям обойти предполагаемые ограничения доступа и читать содержимое кольцевого буфера ядра (kernel ring buffer), используя права суперпользователя (root). Проблема была продемонстрирована в среде Linux Containers (LXC).

Заявление

Red Hat Enterprise Linux 4 находится на этапе Production 3 жизненного цикла поддержки (подробнее), поэтому исправление данной проблемы в будущих обновлениях не планируется. Возможное исправление может быть включено в будущие обновления ядра для Red Hat Enterprise Linux 5, 6 и Red Hat Enterprise MRG.

Затронутые версии ПО

  • Ядро Linux до версии 2.6.39

Тип уязвимости

  • Обход ограничений доступа
  • Чтение чувствительной информации

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4kernelAffected
Red Hat Enterprise Linux 5kernelAffected
Red Hat Enterprise MRG 2realtime-kernelAffected
Red Hat Enterprise Linux 6kernelFixedRHSA-2012:048117.04.2012

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=749243kernel: sysctl: restrict write access to dmesg_restrict

EPSS

Процентиль: 28%
0.00349
Низкий

1.5 Low

CVSS2

Связанные уязвимости

ubuntu
около 14 лет назад

The sysrq_sysctl_handler function in kernel/sysctl.c in the Linux kernel before 2.6.39 does not require the CAP_SYS_ADMIN capability to modify the dmesg_restrict value, which allows local users to bypass intended access restrictions and read the kernel ring buffer by leveraging root privileges, as demonstrated by a root user in a Linux Containers (aka LXC) environment.

nvd
около 14 лет назад

The sysrq_sysctl_handler function in kernel/sysctl.c in the Linux kernel before 2.6.39 does not require the CAP_SYS_ADMIN capability to modify the dmesg_restrict value, which allows local users to bypass intended access restrictions and read the kernel ring buffer by leveraging root privileges, as demonstrated by a root user in a Linux Containers (aka LXC) environment.

debian
около 14 лет назад

The sysrq_sysctl_handler function in kernel/sysctl.c in the Linux kern ...

github
около 4 лет назад

The sysrq_sysctl_handler function in kernel/sysctl.c in the Linux kernel before 2.6.39 does not require the CAP_SYS_ADMIN capability to modify the dmesg_restrict value, which allows local users to bypass intended access restrictions and read the kernel ring buffer by leveraging root privileges, as demonstrated by a root user in a Linux Containers (aka LXC) environment.

EPSS

Процентиль: 28%
0.00349
Низкий

1.5 Low

CVSS2