UBUNTU-CVE-2017-1000365
The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), but does not take the argument and environment pointers into account, which allows attackers to bypass this limitation. This affects Linux Kernel versions 4.11.5 and earlier. It appears that this feature was introduced in the Linux Kernel version 2.6.23.
02 / AFFECTED SOFTWARE
Affected packages
117 explicit affected versions
34 explicit affected versions
56 explicit affected versions
14 explicit affected versions
12 explicit affected versions
17 explicit affected versions
32 explicit affected versions
29 explicit affected versions
26 explicit affected versions
51 explicit affected versions
6 explicit affected versions
12 explicit affected versions
1 explicit affected versions
1 explicit affected versions
23 explicit affected versions
1 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), but does not take the argument and environment pointers into account, which allows attackers to bypass this limitation. This affects Linux Kernel versions 4.11.5 and earlier. It appears that this feature was introduced in the Linux Kernel version 2.6.23.
05 / REFERENCES
Further evidence
- https://patchwork.kernel.org/patch/9803203/
- https://ubuntu.com/security/CVE-2017-1000365
- https://ubuntu.com/security/notices/USN-3377-1
- https://ubuntu.com/security/notices/USN-3377-2
- https://ubuntu.com/security/notices/USN-3378-1
- https://ubuntu.com/security/notices/USN-3378-2
- https://ubuntu.com/security/notices/USN-3381-1
- https://ubuntu.com/security/notices/USN-3381-2
- https://www.cve.org/CVERecord?id=CVE-2017-1000365