Summary: | CVE-2009-2908 kernel ecryptfs NULL pointer dereference | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Josh Bressers <bressers> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | cebbert, davej, dhoward, esandeen, jkacur, jlieskov, jpirko, jskrabal, kyle, lwang, rcvalle |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2010-12-21 19:15:08 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Bug Depends On: | 527834, 527835, 537286 | ||
Bug Blocks: |
Description
Josh Bressers
2009-10-06 20:21:10 UTC
I suspect this flaw could result in arbitrary code execution, but I'm not 100% honestly. The pointer in question does contain function pointers. It's possible it's not, but my limited knowledge tells me to treat is as such. MITRE's CVE-2009-2908 entry: ---------------------------- The d_delete function in fs/ecryptfs/inode.c in eCryptfs in the Linux kernel 2.6.31 allows local users to cause a denial of service (kernel OOPS) and possibly execute arbitrary code via unspecified vectors that cause a "negative dentry" and trigger a NULL pointer dereference, as demonstrated via a Mutt temporary directory in an eCryptfs mount. References: ----------- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2908 https://bugs.launchpad.net/ecryptfs/+bug/387073 http://www.securityfocus.com/bid/36639 http://xforce.iss.net/xforce/xfdb/53693 kernel-2.6.27.37-170.2.104.fc10 has been submitted as an update for Fedora 10. http://admin.fedoraproject.org/updates/kernel-2.6.27.37-170.2.104.fc10 kernel-2.6.27.37-170.2.104.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report. kernel-2.6.30.9-90.fc11 has been submitted as an update for Fedora 11. http://admin.fedoraproject.org/updates/kernel-2.6.30.9-90.fc11 kernel-2.6.30.9-90.fc11 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report. This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2009:1548 https://rhn.redhat.com/errata/RHSA-2009-1548.html |