Hide Forgot
Miroslav Lichvar of Red Hat reports: The last pointer in the list of allocated reply slots that are used to save authenticated cmdmon replies is not initialized. This one was actually found couple months ago and it's already fixed in git, but only recently I realized it could have security implications. An authenticated attacker can allocate and deallocate memory with other commands (e.g. allow/deny) and can force allocation of new reply slots by making new requests and not acknowledging previous replies, and then let chronyd write a reply to an invalid memory.
Acknowledgements: This issue was discovered by Miroslav Lichvár of Red Hat.
Created chrony tracking bugs for this issue: Affects: epel-all [bug 1209633]
Created chrony tracking bugs for this issue: Affects: fedora-all [bug 1209634]
This issue was fixed upstream: http://chrony.tuxfamily.org/News.html The updated version is available at: http://download.tuxfamily.org/chrony/chrony-1.31.1.tar.gz
chrony-2.0-0.3.pre2.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
chrony-1.31.1-1.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report.
chrony-1.31.1-1.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.
chrony-1.31.1-1.el5 has been pushed to the Fedora EPEL 5 stable repository. If problems still persist, please make note of it in this bug report.
chrony-1.31.1-1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2015:2241 https://rhn.redhat.com/errata/RHSA-2015-2241.html