Bug 550001 (CVE-2009-3547) - VUL-0: CVE-2009-3547: kernel: local root exploit in pipe()
Summary: VUL-0: CVE-2009-3547: kernel: local root exploit in pipe()
Status: RESOLVED FIXED
: 553886 (view as bug list)
Alias: CVE-2009-3547
Product: SUSE Security Incidents
Classification: Novell Products
Component: General (show other bugs)
Version: unspecified
Hardware: Other Other
: P2 - High : Critical
Target Milestone: ---
Assignee: Jiri Kosina
QA Contact: Security Team bot
URL:
Whiteboard: wasL3:29696 maint:released:sle10-sp2:...
Keywords: DSLA_REQUIRED, DSLA_SOLUTION_PROVIDED
Depends on:
Blocks:
 
Reported: 2009-10-26 08:57 UTC by Marcus Meissner
Modified: 2017-03-20 21:22 UTC (History)
9 users (show)

See Also:
Found By: Third Party Developer/Partner
Services Priority: 800
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 7 Marcus Meissner 2009-10-27 09:49:33 UTC
current proposed CRD is November 4 (US time)
Comment 8 Swamp Workflow Management 2009-10-29 11:07:31 UTC
The SWAMPID for this issue is 28339.
Please submit the patch and patchinfo file using this ID.
(https://swamp.suse.de/webswamp/wf/28339)
Comment 13 Marcus Meissner 2009-11-03 10:57:42 UTC
is public now:

Reply-To: oss-security@lists.openwall.com
Date: Tue, 03 Nov 2009 18:54:05 +0800
From: Eugene Teo <eugene@redhat.com> 
User-Agent: Thunderbird 2.0.0.21 (X11/20090320)
To: oss-security@lists.openwall.com
Cc: "Steven M. Christey" <coley@linus.mitre.org>
Subject: [oss-security] CVE-2009-3547 kernel: fs: pipe.c null pointer dereference

* a NULL pointer dereference flaw was found in each of the following
functions in the Linux kernel: pipe_read_open(), pipe_write_open(), and
pipe_rdwr_open(). When the mutex lock is not held, the i_pipe pointer
could be released by other processes before it is used to update the
pipe's reader and writer counters. This could lead to a local denial of
service or privilege escalation.

http://lkml.org/lkml/2009/10/14/184
http://lkml.org/lkml/2009/10/21/42
http://git.kernel.org/linus/ad3960243e55320d74195fb85c975e0a8cc4466c
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-3547

Thanks, Eugene
--
Eugene Teo / Red Hat Security Response Team
Comment 15 Jiri Kosina 2009-11-03 11:07:48 UTC
(In reply to comment #13)
> is public now:

I have removed the embargo in SP2/SP3 branches.
Comment 19 Thomas Biege 2009-11-04 19:00:24 UTC
CVE-2009-3547: CVSS v2 Base Score: 9.3 (HIGH) (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Comment 21 Marcus Meissner 2009-11-09 17:09:50 UTC
applied to all relevant kernels now, and in test
Comment 22 Marcus Meissner 2009-11-10 09:57:36 UTC
*** Bug 553886 has been marked as a duplicate of this bug. ***
Comment 23 Marcus Meissner 2009-11-10 16:12:00 UTC
cross checking, the SL110_BRANCH still needs the fix.
Comment 24 Swamp Workflow Management 2009-11-10 23:08:30 UTC
Update released for: kernel-debug, kernel-debug-debuginfo, kernel-default, kernel-default-debuginfo, kernel-source, kernel-source-debuginfo, kernel-syms
Products:
SLE-DEBUGINFO 10-SP2 (ia64)
SLE-SDK 10-SP2 (ia64)
SLE-SERVER 10-SP2 (ia64)
Comment 25 Swamp Workflow Management 2009-11-11 23:08:55 UTC
Update released for: kernel-default, kernel-default-debuginfo, kernel-source, kernel-syms
Products:
SLE-DEBUGINFO 10-SP2 (s390x)
SLE-SERVER 10-SP2 (s390x)
Comment 26 Marcus Meissner 2009-11-12 17:19:54 UTC
A kernel update fixing / mentioning this bug was released on Tuesday for SUSE Linux Enterprise 10 SP2, kernel version 2.6.16.60-0.42.7.
Comment 27 Marcus Meissner 2009-11-12 17:42:05 UTC
A kernel update fixing / mentioning this bug was released today for SUSE Linux Enterprise 10 SP3, kernel version 2.6.16.60-0.57.1.
Comment 28 Jiri Kosina 2009-11-13 14:43:25 UTC
Fix checked in to SL110_BRANCH. Closing.
Comment 29 Swamp Workflow Management 2009-11-13 23:08:30 UTC
Update released for: kernel-s390, kernel-s390-debug, kernel-source, kernel-syms, um-host-kernel, kernel-update.ycp, install-kernel-non-interactive.sh
Products:
SUSE-CORE 9 (s390)
Comment 30 Marcus Meissner 2009-11-16 16:43:14 UTC
A Linux kernel update for SUSE Linux Enterprise Server 9 was released Friday that fixes/mentions this bug. Its version is 2.6.5-7.321.
Comment 31 Swamp Workflow Management 2009-11-17 10:54:03 UTC
The SWAMPID for this issue is 28844.
Please submit the patch and patchinfo file using this ID.
(https://swamp.suse.de/webswamp/wf/28844)
Comment 32 Swamp Workflow Management 2009-11-18 23:08:18 UTC
Update released for: adminfs, novell-cluster-services, novell-cluster-services-cli, novell-cluster-services-km, novell-evms-snapins, novell-nss, novell-sms-zapishim, novell-sms-zapishim-bigsmp, novell-sms-zapishim-default, novell-sms-zapishim-smp, python-xml
Products:
Open-Enterprise-Server 9 (i386)
Comment 33 Swamp Workflow Management 2009-11-18 23:08:24 UTC
Update released for: kernel-bigsmp, kernel-bigsmp-debug, kernel-debug, kernel-debug-debug, kernel-default, kernel-default-debug, kernel-smp, kernel-smp-debug, kernel-source, kernel-syms, kernel-um, kernel-um-debug, kernel-xen, kernel-xen-debug, kernel-xenpae, kernel-xenpae-debug, um-host-install-initrd, um-host-kernel, xen-kmp
Products:
Novell-Linux-Desktop 9 (i386)
Open-Enterprise-Server 9 (i386)
Comment 36 Michal Hocko 2009-12-17 14:43:49 UTC
Starting L3 here
Comment 37 Michal Hocko 2009-12-17 15:10:15 UTC
Patch has been scheduled for the next TD rollup:
sles9sp3 - bug 426350 comment 163
sles10sp1 - bug 434477 commnet 126
Comment 38 Michal Hocko 2009-12-17 15:11:07 UTC
L3 done here
Comment 39 Swamp Workflow Management 2009-12-23 23:09:08 UTC
Update released for: ib-bonding-kmp-rt, ib-bonding-kmp-rt_bigsmp, ib-bonding-kmp-rt_debug, ib-bonding-kmp-rt_timing, kernel-rt, kernel-rt_bigsmp, kernel-rt_debug, kernel-rt_timing, kernel-source, kernel-syms, ofed, ofed-cxgb3-NIC-kmp-rt, ofed-cxgb3-NIC-kmp-rt_bigsmp, ofed-cxgb3-NIC-kmp-rt_debug, ofed-cxgb3-NIC-kmp-rt_timing, ofed-doc, ofed-kmp-rt, ofed-kmp-rt_bigsmp, ofed-kmp-rt_debug, ofed-kmp-rt_timing
Products:
SLE-RT 10-SP2 (i386, x86_64)
Comment 40 Swamp Workflow Management 2010-02-15 12:13:47 UTC
Update released for: acerhk-kmp-debug, acx-kmp-debug, appleir-kmp-debug, at76_usb-kmp-debug, atl2-kmp-debug, aufs-kmp-debug, dazuko-kmp-debug, drbd-kmp-debug, gspcav-kmp-debug, iscsitarget-kmp-debug, ivtv-kmp-debug, kernel-debug, kernel-default, kernel-docs, kernel-kdump, kernel-pae, kernel-ppc64, kernel-ps3, kernel-source, kernel-syms, kernel-vanilla, kernel-xen, kqemu-kmp-debug, nouveau-kmp-debug, omnibook-kmp-debug, pcc-acpi-kmp-debug, pcfclock-kmp-debug, tpctl-kmp-debug, uvcvideo-kmp-debug, virtualbox-ose-kmp-debug, vmware-kmp-debug, wlan-ng-kmp-debug
Products:
openSUSE 11.0 (debug, i386, ppc, x86_64)