Overview
The Linux kernel's Performance Events implementation is susceptible to an out-of-bounds array vulnerability that may be used by a local unprivileged user to escalate privileges.
Description
The Linux kernel's Performance Events implementation is susceptible to an out-of-bounds array vulnerability that may be used by a local unprivileged user to escalate privileges. Additional analysis of the vulnerability may be found in the Red Hat bug report. A public exploit is available that has been reported to work against some Linux distributions. |
Impact
A local authenticated user may be able to exploit this vulnerability to escalate privileges. |
Solution
Apply an Update Red Hat, Debian, CentOS, and Ubuntu have all released patches. Users should receive the patches through their Linux distributions' normal update process.
|
If you are unable to upgrade, please consider the following workaround. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 6.8 | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Temporal | 5.9 | E:ND/RL:OF/RC:C |
Environmental | 4.4 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
- https://rhn.redhat.com/errata/RHSA-2013-0830.html
- http://www.debian.org/security/2013/dsa-2669
- http://www.ubuntu.com/usn/usn-1825-1/
- http://www.ubuntu.com/usn/usn-1826-1/
- http://www.ubuntu.com/usn/usn-1827-1/
- http://www.ubuntu.com/usn/usn-1828-1/
- http://lists.centos.org/pipermail/centos-announce/2013-May/019729.html
- http://lists.centos.org/pipermail/centos-announce/2013-May/019733.html
- https://bugzilla.redhat.com/show_bug.cgi?id=962792
- https://bugzilla.redhat.com/show_bug.cgi?id=962792#c16
- https://bugzilla.redhat.com/show_bug.cgi?id=962799
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b0a873ebbf87bf38bf70b5e39a7cadc96099fa13
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/kernel/events/core.c?id=8176cced706b5e5d15887584150764894e94e02f
- http://packetstormsecurity.com/files/121616/semtex.c
- http://lkml.indiana.edu/hypermail/linux/kernel/1304.1/03652.html
- http://www.reddit.com/r/netsec/comments/1eb9iw/sdfucksheeporgs_semtexc_local_linux_root_exploit/c9ykrck
Acknowledgements
Tommi Rantala discovered this vulnerability.
This document was written by Jared Allar.
Other Information
CVE IDs: | CVE-2013-2094 |
Date Public: | 2013-05-14 |
Date First Published: | 2013-05-17 |
Date Last Updated: | 2013-05-17 16:00 UTC |
Document Revision: | 28 |