Bug 157454

Summary: CAN-2005-1263 Linux kernel ELF core dump privilege elevation
Product: [Fedora] Fedora Reporter: Mark J. Cox <mjc>
Component: kernelAssignee: Dave Jones <davej>
Status: CLOSED ERRATA QA Contact: Brian Brock <bbrock>
Severity: medium Docs Contact:
Priority: medium    
Version: 3CC: mattdm, pdemauro, pfrields, wtogami
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2005-05-23 18:23:42 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
Proposed patch from Greg KH (not backported) none

Description Mark J. Cox 2005-05-11 18:35:42 UTC
+++ This bug was initially created as a clone of Bug #157450 +++

"A locally exploitable flaw has been found in the Linux ELF binary format
loader's core dump  function  that  allows  local  users  to  gain  root
privileges and also execute arbitrary code at kernel privilege level."

For the full description see
http://www.securityfocus.com/archive/1/397966/2005-05-08/2005-05-14/0

Comment 1 Mark J. Cox 2005-05-11 18:35:42 UTC
Created attachment 114255 [details]
Proposed patch from Greg KH (not backported)

Comment 2 Dave Jones 2005-05-17 23:56:12 UTC
rebased to 2.6.11.10 for latest update, will go live soon.


Comment 5 Mark J. Cox 2005-05-23 18:23:42 UTC
Fixed by FEDORA-2005-392