New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 596314 link

Starred by 1 user

Issue metadata

Status: Duplicate
Owner:
Last visit > 30 days ago
Closed: Mar 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 1
Type: Bug-Security



Sign in to add a comment

Security: Chrome OS [CVE-2016-0728]

Reported by eternalg...@gmail.com, Mar 20 2016

Issue description




VULNERABILITY DETAILS
A use-after-free flaw was found in the way the Linux kernel's key management subsystem handled keyring object reference counting in certain error path of the join_session_keyring() function. A local, unprivileged user could use this flaw to escalate their privileges on the system.

VERSION
Operating System: ChromeOS current master branch

REPRODUCTION CASE
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and use-after-free) via crafted keyctl commands. 

MITIGATION
Update to kernmel 4.4.1 or higher.
Or apply this patch: https://bugzilla.redhat.com/show_bug.cgi?id=1297475#c13

 

Comment 1 by mea...@chromium.org, Mar 20 2016

Cc: kerrnel@chromium.org mdempsky@chromium.org
+mdempsky, kerrnel: Can you please triage?

Comment 2 by mea...@chromium.org, Mar 20 2016

Labels: OS-Chrome
Owner: mdempsky@chromium.org
Matthew, mind taking a look since this is in the kernel? Thanks.

Comment 4 by mea...@chromium.org, Mar 21 2016

Status: Assigned (was: Unconfirmed)

Comment 5 by wfh@chromium.org, Mar 23 2016

Labels: Security_Severity-High Security_Impact-Stable Pri-1

Comment 6 by wfh@chromium.org, Mar 24 2016

Components: OS>Kernel
Project Member

Comment 7 by sheriffbot@chromium.org, Mar 24 2016

Labels: M-49
Cc: cernekee@chromium.org
Mergedinto: 579179
Status: Duplicate (was: Assigned)
cernekee@ fixed this back in January.
Project Member

Comment 9 by sheriffbot@chromium.org, Jul 5 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 10 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment