Bug 1033458 - (CVE-2017-7286) VUL-0: CVE-2017-7286: kernel-source: Inode integer overflow
(CVE-2017-7286)
VUL-0: CVE-2017-7286: kernel-source: Inode integer overflow
Status: RESOLVED INVALID
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Minor
: ---
Assigned To: E-mail List
E-mail List
https://smash.suse.de/issue/183325/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2017-04-11 07:06 UTC by Marcus Meissner
Modified: 2017-04-13 11:27 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
CVE-2017-7286.c (436 bytes, text/plain)
2017-04-11 07:30 UTC, Marcus Meissner
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2017-04-11 07:06:47 UTC
rh#1440871

The Linux kernel package 3.16.0-28 on Ubuntu 14.04 LTS mishandles a series of
mmap system calls for /dev/zero with different starting addresses, with a stated
impact of "allowing for a local user to possibly gain root access," aka an
"inode integer overflow."

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1440871
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-7286
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7286
https://packetstormsecurity.com/files/141930/Linux-3.16.0-28-Integer-Overflow.html
Comment 1 Marcus Meissner 2017-04-11 07:30:25 UTC
Created attachment 720674 [details]
CVE-2017-7286.c

QA RERPODUCER:

gcc -o CVE-2017-7286 CVE-2017-7286.c -Wall -O2 -pie -fPIE
./CVE-2017-7286

(using PIE to get a higher startaddress to avoid itself overwriting its own code)
Comment 2 Marcus Meissner 2017-04-11 07:32:23 UTC
Does not show bad behaviour on Tumbleweed.
Comment 3 Marcus Meissner 2017-04-11 07:34:56 UTC
The reporter likely crashed its own main() in the packetstorm report, as the mmap() will overwrite main() pretty soon.
Comment 4 Marcus Meissner 2017-04-11 07:40:04 UTC
(I call bullshit on this report :( )
Comment 5 Marcus Meissner 2017-04-13 11:27:36 UTC
I emailed the reporter and he has no other proof than his reproducer crashing.

I asked Mitre to REJECT the CVE.