Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1625050 - (CVE-2018-16402) CVE-2018-16402 elfutils: Double-free due to double decompression of sections in crafted ELF causes crash
CVE-2018-16402 elfutils: Double-free due to double decompression of sections ...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
impact=low,public=20180815,reported=2...
: Security
Depends On: 1625052 1625399 1625400 1625401 1625051
Blocks: 1625054
  Show dependency treegraph
 
Reported: 2018-09-04 00:26 EDT by Sam Fowler
Modified: 2018-10-24 08:36 EDT (History)
25 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Sam Fowler 2018-09-04 00:26:47 EDT
Elfutils through version 0.173 is vulnerable to a double-free in the libelf/elf_end.c:elf_end() function due to the decompression of section data multiple times.. An attacker could exploit this to cause a crash or possibly have unspecified other impact via a crafted ELF.


Upstream Bug:

https://sourceware.org/bugzilla/show_bug.cgi?id=23528


Upstream Patch:

https://sourceware.org/git/?p=elfutils.git;a=patch;h=56b18521fb8d46d40fc090c0de9d11a08bc982fa
Comment 1 Sam Fowler 2018-09-04 00:27:37 EDT
Created elfutils tracking bugs for this issue:

Affects: fedora-all [bug 1625051]
Comment 4 Scott Gayou 2018-09-04 15:46:04 EDT
Reproduced on 7+ quite easily. Did not reproduce on 5/6. 6 was running 0.164.
Comment 6 Mark Wielaard 2018-09-04 16:03:42 EDT
(In reply to Scott Gayou from comment #4)
> Reproduced on 7+ quite easily. Did not reproduce on 5/6. 6 was running 0.164.

That makes sense, support for compressed ELF sections was introduced in elfutils 0.165.

Note You need to log in before you can comment on or make changes to this bug.