oss-sec mailing list archives
Re: CVE-2018-1130: Linux kernel: dccp: a null pointer dereference in net/dccp/output.c:dccp_write_xmit
From: Andrey Konovalov <andreyknvl () gmail com>
Date: Fri, 25 May 2018 17:07:08 +0200
On Fri, May 25, 2018 at 2:04 PM, Evgenii Shatokhin <eshatokhin () virtuozzo com> wrote:
If I understand it correctly, Syzkaller programs run as root. Therefore, it is still needed to check which of the bugs it has found are security flaws.
No, syzkaller/syzbot runs programs in a user namespace, so any distro that allows unprivileged users to create user namespaces (e.g. Ubuntu) is vulnerable to most of the bugs syzbot finds. But nevertheless all those bugs need to be checked whether they actually are security flaws, and that requires quite a lot of effort.
As for this particular bug in dccp_write_xmit() - I stumbled upon that Syzbot's report and checked that the bug was exploitable by an unprivileged user if dccp modules were loaded. Then I reported the problem to RedHat, and they desided to request a CVE for that. The problem is not critical for RHEL, by the way, but still. I don't know, if the process was the same for other bugs found by Syzkaller they requested CVEs for.
OK, if the process was like that for the rest of those bugs, that explains a somewhat random selection of syzbot bugs for which CVEs were assigned :) Thanks!
Current thread:
- CVE-2018-1130: Linux kernel: dccp: a null pointer dereference in net/dccp/output.c:dccp_write_xmit Vladis Dronov (May 10)
- Re: CVE-2018-1130: Linux kernel: dccp: a null pointer dereference in net/dccp/output.c:dccp_write_xmit Andrey Konovalov (May 23)
- Re: CVE-2018-1130: Linux kernel: dccp: a null pointer dereference in net/dccp/output.c:dccp_write_xmit Kurt Seifried (May 23)
- Re: CVE-2018-1130: Linux kernel: dccp: a null pointer dereference in net/dccp/output.c:dccp_write_xmit Andrey Konovalov (May 25)
- Re: CVE-2018-1130: Linux kernel: dccp: a null pointer dereference in net/dccp/output.c:dccp_write_xmit Evgenii Shatokhin (May 25)
- Re: CVE-2018-1130: Linux kernel: dccp: a null pointer dereference in net/dccp/output.c:dccp_write_xmit Andrey Konovalov (May 25)
- Re: CVE-2018-1130: Linux kernel: dccp: a null pointer dereference in net/dccp/output.c:dccp_write_xmit Kurt Seifried (May 25)
- Re: CVE-2018-1130: Linux kernel: dccp: a null pointer dereference in net/dccp/output.c:dccp_write_xmit Andrey Konovalov (May 25)
- Re: CVE-2018-1130: Linux kernel: dccp: a null pointer dereference in net/dccp/output.c:dccp_write_xmit Kurt Seifried (May 23)
- Re: CVE-2018-1130: Linux kernel: dccp: a null pointer dereference in net/dccp/output.c:dccp_write_xmit Andrey Konovalov (May 23)