Bug 1403817 (CVE-2015-8966) - CVE-2015-8966 kernel: Local privileges escalation via crafted F_OFD_GETLK/F_OFD_SETLK/F_OFD_SETLKW commands
Summary: CVE-2015-8966 kernel: Local privileges escalation via crafted F_OFD_GETLK/F_O...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2015-8966
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1403821
TreeView+ depends on / blocked
 
Reported: 2016-12-12 12:29 UTC by Adam Mariš
Modified: 2021-02-17 02:53 UTC (History)
35 users (show)

Fixed In Version: kernel 4.4
Clone Of:
Environment:
Last Closed: 2017-01-18 12:29:57 UTC
Embargoed:


Attachments (Terms of Use)

Description Adam Mariš 2016-12-12 12:29:18 UTC
arch/arm/kernel/sys_oabi-compat.c in the Linux kernel before 4.4 allows local users to gain privileges via a crafted (1) F_OFD_GETLK, (2) F_OFD_SETLK, or (3) F_OFD_SETLKW command in an fcntl64 system call.

Initial message:

https://source.android.com/security/bulletin/2016-12-01.html#eop-in-kernel

Upstream patch:

https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=76cc404bfdc0d419c720de4daaf2584542734f42

Comment 3 Vladis Dronov 2017-01-18 12:29:57 UTC
Statement:

This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG-2 as the code with the flaw is not built in the products listed.


Note You need to log in before you can comment on or make changes to this bug.