oss-sec mailing list archives

CVE-Request: Linux ASLR mmap weakness: Reducing entropy by half


From: Hector Marco <hecmargi () upv es>
Date: Wed, 18 Feb 2015 12:01:37 +0100

Hi,

A bug in Linux ASLR implementation for versions prior to 3.19 has been found. The issue is that the mmap area for processes is not properly randomized on some architectures.

Affected systems have reduced the mmap base area entropy of the processes by half.


Details at:
http://hmarco.org/bugs/linux-ASLR-reducing-mmap-by-half.html



Could you please assign a CVE-ID for this?



Hector Marco.
http://hmarco.org

Cyber-security researcher at
http://cybersecurity.upv.es/


Current thread: