oss-sec mailing list archives
CVE-2014-7970: Linux VFS denial of service
From: Andy Lutomirski <luto () amacapital net>
Date: Wed, 8 Oct 2014 12:48:19 -0700
pivot_root has a bug. Exploiting it at all is tricky, but it can be done. I'm reasonably confident that this is just denial of service. (There's also probably an information disclosure in there, but I think that it's only available to root, so it's not a big deal.) I'm posting this a little bit early, since a patch is publicly available, the impact is low, and hitting the bad code path at all is quite tedious. I'll send a proof of concept later on. Distros: if you need a test case to validate the fix, let me know. Although, for validation, it should be sufficient to just chroot somewhere as root, escape the chroot (while still chrooted), and then pivot_root(".", ".") on a mountpoint. Candidate patch here: http://news.gmane.org/find-root.php?message_id=87bnpmihks.fsf%40x220.int.ebiederm.org -- Andy Lutomirski AMA Capital Management, LLC
Current thread:
- CVE-2014-7970: Linux VFS denial of service Andy Lutomirski (Oct 08)
- Re: CVE-2014-7970: Linux VFS denial of service Andy Lutomirski (Oct 17)
- Re: CVE-2014-7970: Linux VFS denial of service cve-assign (Oct 17)
- Re: CVE-2014-7970: Linux VFS denial of service Andy Lutomirski (Oct 17)