Executive brief
The Linux kernel load_elf_binary() function fails to allocate sufficient space for PIE binaries when CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE is enabled. This results in subsequent PT_LOAD segments being mapped into the memory gap reserved for the stack, leading to memory corruption and potential local privilege escalation.
Affected products
- Linux Linux Kernel Long-term kernels prior to April 2015 (backported to 3.10.77)
Timeline
- 2015-04-14: patched: Initial fix committed to Linux kernel (commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86)
- 2015-05: patched: Backported to Linux 3.10.77
- 2017-09-26: disclosed: Public advisory by Qualys released
- 2024-09-09: kev added: Added to CISA Known Exploited Vulnerabilities Catalog