Bug 174075
Summary: | [RHEL4] CVE-2005-3783 ptrace DoS | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 4 | Reporter: | Mark J. Cox <mjc> |
Component: | kernel | Assignee: | Peter Staubach <staubach> |
Status: | CLOSED WONTFIX | QA Contact: | Brian Brock <bbrock> |
Severity: | high | Docs Contact: | |
Priority: | medium | ||
Version: | 4.0 | CC: | jbaron |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | source=cve,reported=20051123,impact=important,public=20051109 | ||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2006-01-05 16:48:29 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Mark J. Cox
2005-11-24 10:37:19 UTC
This is a change to the user ABI and should not go into RHEL4. The 2.6.14-stable branch upstream should not have put it in, IMHO. Linus has decided that for 2.6.15 this ABI change is worth the risk and he'll wait to hear users complain about it rather than worrying ahead of time. We know from past reports that people have used ptrace in this way (one thread to another within a process); such uses were probably ill-advised practice in the first place, but if any exist in applications then changing this in RHEL4 would be a problem for customers. There were various crash or leak bugs (DoS potential) relating to this usage pattern, but AFAIK each individual problem has been addressed upstream (and I think those fixes backported to RHEL4, though I am not positive). AIUI, the upstream change was not because there is any current crash or DoS problem left, but because Linus decided it would be easier to rule out the hairy class of usage patterns entirely than to worry about stumbling across another such case since we already found and fixed a few cases peculiar to this usage pattern. If there are particular crash/leak/DoS failure modes in RHEL4 ptrace use, those should be filed as specific bugs and addressed directly. |