grsecurity Role-Based Access Control (RBAC) security bypass

grsecurity-rbac-security-bypass (41952) The risk level is classified as LowLow Risk

Description:

grsecurity could allow a local attacker to bypass security restrictions, caused by an error in the user_transition_deny and user_transition_allow Role-Based Access Control (RBAC) system rules. An attacker could exploit this vulnerability via calls to sys_setfsuid() and sys_setfsgid() to bypass RBAC system rules.

Platforms Affected:

  • grsecurity, grsecurity

Remedy:

Upgrade to the latest version of grsecurity (2.1.11-2.6.24.5 or 2.1.11-2.4.36.2 or later), available from the grsecurity Download Web site. See References.

Consequences:

Bypass Security

References:

  • grsecurity Download Web site, grsecurity-2.1.11-2.4.36.2-200804211830.patch.gz at http://www.grsecurity.org/download.php.
  • grsecurity News Web site, [04/21] grsecurity 2.1.11 patches updated, 2.6.24.5 supported at http://www.grsecurity.org/news.php.
  • BID-28889: grsecurity Multiple RBAC Local Security Bypass Vulnerabilities
  • CVE-2008-1940: The RBAC functionality in grsecurity before 2.1.11-2.6.24.5 and 2.1.11-2.4.36.2 does not enforce user_transition_deny and user_transition_allow rules for the (1) sys_setfsuid and (2) sys_setfsgid calls, which allows local users to bypass restrictions for those calls.
  • SA29899: grsecurity RBAC User Transition Security Issue
  • SECTRACK ID: 1019919: grsecurity Lets Local Users Bypass Role Based Access Control Rules
  • VUPEN/ADV-2008-1323: grsecurity RBAC User Transition Rules Local Security Bypass Issue

Reported:

Apr 21, 2008

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page