Junglewise Threat Intelligence

CVE-2017-1000253: Linux Kernel PIE Stack Buffer Corruption Vulnerability

CVE-2017-1000253 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2024-09-09

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel load_elf_binary() function fails to allocate sufficient space for PIE binaries when CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE is enabled. This results in subsequent PT_LOAD segments being mapped into the memory gap reserved for the stack, leading to memory corruption and potential local privilege escalation.

Affected products

  • Linux Linux Kernel Long-term kernels prior to April 2015 (backported to 3.10.77)

Timeline

  • 2015-04-14: patched: Initial fix committed to Linux kernel (commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86)
  • 2015-05: patched: Backported to Linux 3.10.77
  • 2017-09-26: disclosed: Public advisory by Qualys released
  • 2024-09-09: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats