Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok restrictions, overwrite arbitrary kernel memory locations, and gain privileges by leveraging a (1) BUG, (2) NULL pointer dereference, or (3) page fault, as demonstrated by vectors involving the clear_child_tid feature and the splice system call.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Linux kernel kernel/exit.c文件权限许可和访问控制问题漏洞
Vulnerability Description
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。NFSv4 implementation是其中的一个分布式文件系统协议。 Linux kernel 2.6.36.2之前版本中的kernel/exit.c文件中的do_exit函数没有正确处理KERNEL_DS get_fs值。本地用户可以通过利用(1)BUG,(2)空指针解引用,或者(3)页面错误绕过预设的access_ok限制,覆盖任意内核内存地址,并获取特权。该漏洞已经通过clear_child_tid功能,以及
CVSS Information
N/A
Vulnerability Type
N/A