Skip to main content

FYI - exploit in the wild against SLF 6 kernels


While we are not declaring a critical vulnerability, this is information that you should know.  There is a zero day exploit in the wild that can work against SLF 6.  This *does* require local access, but privilege escalation is pretty trivial.  There is a workaround available.

- Full vulnerability information will be tracked as CVE-2013-2094 (just a candidate currently).
- This is a bug that needs PERF_EVENTS be compiled into the kernel, which is by default on most distros (including SL/SLF).
- This bug affects kernels 2.6.37 to 3.8.8.  While this is a "new" bug, it affects 2.6.37 due to being backported.
- The bug also got backported into kernel 2.6.32 on CentOS, RHEL, and SL/SLF.

- Since SL/SLF 6 uses kernel 2.6.32-71, it is vulnerable.

(As an FYI, version 5 uses kernel 2.6.18-8 and is not vulnerable)


The workaround is setting kernel.perf_event_paranoid to a value of 2, e.g.,

# /bin/sysctl kernel.perf_event_paranoid=2

(values are as follows: -1 = not paranoid, 0 = disallow raw tracepoint access for unpriv, 1 = disallow cpu events for unpriv, and 2 = disallow kernel profiling for unpriv)

By setting this parameter to 2, unprivileged users won't be able to get kernel profiling data (e.g., via the perf command).  This shouldn't affect a lot of people.

As such, CST recommends that if you are using SLF 6, please set the perf_event_paranoid kernel parameter to 2.


Thanks,
- Art Lee

Comments

Popular posts from this blog

OWASP Top 10 Threats and Mitigations Exam - Single Select

Last updated 4 Aug 11 Course Title: OWASP Top 10 Threats and Mitigation Exam Questions - Single Select 1) Which of the following consequences is most likely to occur due to an injection attack? Spoofing Cross-site request forgery Denial of service   Correct Insecure direct object references 2) Your application is created using a language that does not support a clear distinction between code and data. Which vulnerability is most likely to occur in your application? Injection   Correct Insecure direct object references Failure to restrict URL access Insufficient transport layer protection 3) Which of the following scenarios is most likely to cause an injection attack? Unvalidated input is embedded in an instruction stream.   Correct Unvalidated input can be distinguished from valid instructions. A Web application does not validate a client’s access to a resource. A Web action performs an operation on behalf of the user without checkin...

CKA Simulator Kubernetes 1.22

  https://killer.sh Pre Setup Once you've gained access to your terminal it might be wise to spend ~1 minute to setup your environment. You could set these: alias k = kubectl                         # will already be pre-configured export do = "--dry-run=client -o yaml"     # k get pod x $do export now = "--force --grace-period 0"   # k delete pod x $now Vim To make vim use 2 spaces for a tab edit ~/.vimrc to contain: set tabstop=2 set expandtab set shiftwidth=2 More setup suggestions are in the tips section .     Question 1 | Contexts Task weight: 1%   You have access to multiple clusters from your main terminal through kubectl contexts. Write all those context names into /opt/course/1/contexts . Next write a command to display the current context into /opt/course/1/context_default_kubectl.sh , the command should use kubectl . Finally write a second command doing the same thing into ...