Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-13166

Опубликовано: 20 июл. 2017
Источник: redhat
CVSS3: 7.8

Описание

An elevation of privilege vulnerability in the kernel v4l2 video driver. Product: Android. Versions: Android kernel. Android ID A-34624167.

A bug in the 32-bit compatibility layer of the ioctl handling code of the v4l2 video driver in the Linux kernel has been found. A memory protection mechanism ensuring that user-provided buffers always point to a userspace memory were disabled, allowing destination address to be in a kernel space. This flaw could be exploited by an attacker to overwrite a kernel memory from an unprivileged userspace process, leading to privilege escalation.

Меры по смягчению последствий

A systemtap script intercepting v4l2_compat_ioctl32() function of the [videodev] module and making it to return -ENOIOCTLCMD error value would work just fine, except breaking all 32bit video capturing software, but not 64bit ones. Alternatively, blacklisting [videodev] module will work too, but it will break all video capturing software.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelWill not fix
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 6kernelFixedRHSA-2018:131908.05.2018
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2018:067610.04.2018
Red Hat Enterprise Linux 7kernelFixedRHSA-2018:106210.04.2018
Red Hat Enterprise Linux 7kernel-altFixedRHSA-2018:294830.10.2018
Red Hat Enterprise Linux 7.4 Extended Update SupportkernelFixedRHSA-2018:113017.04.2018
Red Hat Enterprise MRG 2kernel-rtFixedRHSA-2018:117017.04.2018

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=1548412kernel: v4l2: disabled memory access protection mechanism allowing privilege escalation

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 7 лет назад

An elevation of privilege vulnerability in the kernel v4l2 video driver. Product: Android. Versions: Android kernel. Android ID A-34624167.

CVSS3: 7.8
nvd
больше 7 лет назад

An elevation of privilege vulnerability in the kernel v4l2 video driver. Product: Android. Versions: Android kernel. Android ID A-34624167.

CVSS3: 7.8
debian
больше 7 лет назад

An elevation of privilege vulnerability in the kernel v4l2 video drive ...

CVSS3: 7.8
github
около 3 лет назад

An elevation of privilege vulnerability in the kernel v4l2 video driver. Product: Android. Versions: Android kernel. Android ID A-34624167.

suse-cvrf
около 7 лет назад

Security update for the Linux Kernel (Live Patch 27 for SLE 12)

7.8 High

CVSS3