Back to search
CVE-2011-0726
Published: Jul 18, 2011
Modified: Aug 6, 2024
PUBLISHED
Description
The do_task_stat function in fs/proc/array.c in the Linux kernel before 2.6.39-rc1 does not perform an expected uid check, which makes it easier for local users to defeat the ASLR protection mechanism by reading the start_code and end_code fields in the /proc/#####/stat file for a process executing a PIE binary.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[mm-commits] 20110314 + proc-protect-mm-start_code-end_code-in-proc-pid-stat.patch added to -mm tree
mailing-list
x_refsource_MLIST
https://bugzilla.redhat.com/show_bug.cgi?id=684569
x_refsource_CONFIRM
47791
vdb-entry
x_refsource_BID
RHSA-2011:0833
vendor-advisory
x_refsource_REDHAT
http://downloads.avaya.com/css/P8/documents/100145416
x_refsource_CONFIRM
[linux-kernel] 20110311 [PATCH] proc: protect mm start_code/end_code in /proc/pid/stat
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now