|
|
Log in / Subscribe / Register

Security

A flurry of kernel security fixes

April 26, 2006

This article was contributed by Jake Edge.

Over the last month, there have been eleven separate releases in the 2.6.16 stable kernel series, seven of which were single-patch releases for security related issues. This flurry of security fixes would make one think that there was a concerted effort by an individual or organization to try and find kernel security problems, but that is not the case. It is entirely coincidental that all of these fixes came about at around the same time.

A chronological look at each of these fixes gives a nice picture of the diverse places that kernel developers are looking for bugs in general and security bugs in particular.

Roughly a week after the original 2.6.16 release, the 2.6.16.1 release contained 19 patches, including one that fixed CVE-2006-1242. Code had been put into the kernel in the 2.4 series to stop leaking information in the form of fragment IDs in TCP packets that did not require them. Packets that have the DF (don't fragment) bit set do not need a fragment ID and eliminating that information is a countermeasure to a technique called idle scanning. Unfortunately when the original change was made, the response to a certain kind of packet (a SYN-ACK packet) was missed and that was discovered in March.

The 2.6.16.2 release came out on 7 April and had a quite a few fixes including a change to the sysfs interface covered by LWN two weeks ago.

On the 11th and 12th of April, there were 3 releases, each of which included just one security fix. 2.6.16.3 is a fix for a bug that would allow a user to oops the kernel by passing invalid arguments to the keyctl utility (CVE-2006-1522). If the user specified a key as the target for an "add key" operation, rather than a keyring, a invalid dereference in the kernel would result.

A call to BUG_ON() in the __group_complete_signal() function (which is part of the RCU signal handling code) "has unknown impact and attack vectors" and was patched as 2.6.16.4. If a user process could cause the condition in the BUG_ON call, it could oops the kernel and lead to a denial of service. (CVE-2006-1523).

A difference in the way Intel and AMD 64-bit CPUs handle non-canonical return addresses led to the 2.6.16.5 release. The Intel CPU reports the exception on the SYSRET instruction which causes the kernel exception handler to run using the user stack. (CVE-2006-0744). Kernel processing using a user created stack would seem rife with opportunities for exploitation.

The 2.6.16.6 release came out a week later with another long list of patches, two of which have security implications. The m32r architecture had a bug in the get_user and put_user macros that did not check the address passed to them which would allow access outside of the process address space.

A more widespread issue was addressed with a patch in this release and then fixed in the 2.6.16.7 release later in the day. The MADV_REMOVE vulnerability (CVE-2006-1524) has been present in kernels since 2.4 and allows local users to potentially bypass the access restrictions on a read-only attachment of shared memory. The user process could call mprotect() and gain write permission on a piece of memory even though the memory was explicitly set to be read-only when shared via the shared memory IPC mechanism.

Prior to 2.6.16.8, the kernel was vulnerable to users causing a kernel panic by requesting a route for a multicast IP address (CVE-2006-1525). Using a simple 'ip' command from the shell would cause a null pointer dereference in ip_route_input and panic the kernel. This is another example of a local denial of service vulnerability.

2.6.16.9 patches a problem that affected both Linux and FreeBSD kernels running on AMD processors which would allow a malicious process running on the same CPU to determine portions of the state of floating point instructions in a target process. AMD had some comments on the bug and provided some background information on why they chose to implement the FXRSTOR and FXSAVE instructions differently than they are implemented in Intel processors. Essentially, these two instructions do not save and restore all of the same registers as Intel does and this allows information to leak from one process to another. The patch ensures that the floating point state is constant between context switches on affected processors. (CVE-2006-1056)

Last on our tour of kernel security fixes is a patch made in 2.6.16.11 and released on Monday that disallows backslashes in path components unless POSIX paths have been negotiated. This change is for the CIFS (aka Samba) filesystem code; one can only imagine the kinds of havoc one could cause by putting backslashes (the standard Windows path separator) into CIFS paths. This bug is CVE-2006-1863, but the CVE database just shows a placeholder page for that number at the time of this writing.

Observant readers will have noticed that we skipped over 2.6.16.10 as it was a release with quite a few patches, none of which were noted as being security related.

As this laundry list of issues shows, there are a wide variety of places that kernel bugs can impact security, but the many eyes of kernel developers seem to be finding and fixing them. This process plays out in the open and that can give competitors ammunition to claim that Linux is less secure than certain proprietary systems. Reasonable people would more likely come to the conclusion that Linux developers are much more interested in finding these issues and fixing them. The kernel community has no interest in hiding vulnerabilities or playing games with security patch descriptions to make the OS look more secure. PR considerations just do not seem to be on the radar of the technical contributors and that is just as it should be.

Comments (2 posted)

New vulnerabilities

abc2ps: buffer overflows

Package(s):abc2ps abcmidi CVE #(s):CVE-2006-1513 CVE-2006-1514
Created:April 25, 2006 Updated:April 26, 2006
Description: Erik Sjölund discovered that abc2ps, a translator for ABC music description files into PostScript, does not check the boundaries when reading in ABC music files resulting in buffer overflows.

The abcmidi-yaps utility suffers from similar problems.

Alerts:
Debian DSA-1043-1 abcmidi 2006-04-26
Debian DSA-1041-1 abc2ps 2006-04-25

Comments (none posted)

beagle: command line injection

Package(s):beagle CVE #(s):
Created:April 21, 2006 Updated:April 26, 2006
Description: Chris Evans discovered that while indexing, Beagle will build certain command lines in an insecure manner. When Beagle executes external helper applications, it is possible to cause beagle to execute arbitrary commands as the user running beagle.
Alerts:
Fedora FEDORA-2006-440 beagle 2006-04-21

Comments (none posted)

ethereal: multiple vulnerabilities

Package(s):ethereal CVE #(s):CVE-2006-1937 CVE-2006-1933 CVE-2006-1932 CVE-2006-1935 CVE-2006-1934 CVE-2006-1938 CVE-2006-1939 CVE-2006-1940 CVE-2006-1936
Created:April 25, 2006 Updated:May 12, 2006
Description: There are multiple vulnerabilities in Ethereal version up to 0.10.14, including various dissector crashes and an off-by-one error in the OID printing routine.
Alerts:
SuSE SUSE-SR:2006:010 opera, pdns, cpio, ethereal, clamav, apache 2006-05-12
Red Hat RHSA-2006:0420-01 Ethereal 2006-05-03
Debian DSA-1049-1 ethereal 2006-05-02
Gentoo 200604-17 ethereal 2006-04-27
Mandriva MDKSA-2006:077 ethereal 2006-04-25
Fedora FEDORA-2006-461 ethereal 2006-04-26
Fedora FEDORA-2006-456 ethereal 2006-04-25

Comments (none posted)

fbida: insecure temporary file creation

Package(s):fbida CVE #(s):CVE-2006-1695
Created:April 24, 2006 Updated:May 22, 2006
Description: The fbgs script in the fbi package 2.01-1.4, when the TMPDIR environment variable is not defined, allows local users to overwrite arbitrary files via a symlink attack on temporary files in /var/tmp/fbps-[PID].
Alerts:
Debian DSA-1068-1 fbi 2006-05-20
Gentoo 200604-13 fbida 2006-04-23

Comments (none posted)

kernel: multiple vulnerabilities

Package(s):kernel CVE #(s):CVE-2006-1056 CVE-2006-1525 CVE-2006-1524 CVE-2006-0744 CVE-2006-1522 CVE-2006-1055
Created:April 20, 2006 Updated:May 4, 2006
Description: Multiple kernel vulnerabilities have been fixed, including an x87 information leak between processes, an ip_route_input panic, a MADV_REMOVE vulnerability, an mprotect write permission problem, insecure MPBL0010 driver sysfs permissions, an x86_64 force IRET issue, RCU signal handling, a key addition oops, a sysfs write buffer issue and more.
Alerts:
SUSE SUSE-SU-2014:0446-1 Xen 2014-03-25
Ubuntu USN-281-1 linux-source-2.6.10, linux-source-2.6.12 2006-05-04
Trustix TSLSA-2006-0022 kernel 2006-04-21
Fedora FEDORA-2006-423 kernel 2006-04-20
Fedora FEDORA-2006-421 kernel 2006-04-19

Comments (none posted)

php: several vulnerabilities

Package(s):php CVE #(s):CVE-2006-0996 CVE-2006-1494 CVE-2006-1608
Created:April 25, 2006 Updated:May 24, 2006
Description: There are several vulnerabilities in PHP v5.1.2 and earlier.
  • A cross-site scripting (XSS) vulnerability in phpinfo (info.c) allows remote attackers to inject arbitrary web script or HTML via long array variables. (CVE-2006-0996)
  • A directory traversal vulnerability in file.c allows local users to bypass open_basedir restrictions and allows remote attackers to create files in arbitrary directories via the tempnam function. (CVE-2006-1494)
  • The copy function in file.c allows local users to bypass safe mode and read arbitrary files via a source argument containing a compress.zlib:// URI. (CVE-2006-1608)
Alerts:
Red Hat RHSA-2006:0501-02 PHP 2006-05-23
Fedora FEDORA-2006-289 php 2006-05-16
Gentoo 200605-08 php 2006-05-08
SuSE SUSE-SA:2006:024 php4,php5 2006-05-05
Red Hat RHSA-2006:0276-01 PHP 2006-04-25
Mandriva MDKSA-2006:074 php 2006-04-24

Comments (none posted)

ruby1.8: denial of service

Package(s):ruby1.8 CVE #(s):CVE-2006-1931
Created:April 24, 2006 Updated:May 10, 2006
Description: The HTTP/XMLRPC server in Ruby before 1.8.2 uses blocking sockets, which allows attackers to cause a denial of service (blocked connections) via a large amount of data.
Alerts:
Gentoo 200605-11 ruby 2006-05-10
Red Hat RHSA-2006:0427-01 ruby 2006-05-09
Mandriva MDKSA-2006:079 ruby 2006-04-25
Ubuntu USN-273-1 ruby1.8 2006-04-24

Comments (none posted)

xzgv: heap overflow

Package(s):xzgv CVE #(s):CVE-2006-1060
Created:April 21, 2006 Updated:June 12, 2006
Description: Andrea Barisani of Gentoo Linux discovered xzgv and zgv allocate insufficient memory when rendering images with more than 3 output components, such as images using the YCCK or CMYK colour space. When xzgv or zgv attempt to render the image, data from the image overruns a heap allocated buffer.
Alerts:
Gentoo 200604-10:02 zgv 2006-04-21
Debian DSA-1038-1 xzgv 2006-04-22
Debian DSA-1037-1 zgv 2006-04-21
Gentoo 200604-10 xzgv 2006-04-21

Comments (none posted)

Page editor: Jonathan Corbet
Next page: Kernel development>>


Copyright © 2006, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds