CONFERENCE Cloud & Data Security Summit - Watch Sessions on Demand
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

‘Stack Clash’ Flaws Allow Privilege Escalation on Unix Systems

Linux and other Unix-like operating systems are affected by a type of vulnerability that can be exploited by an attacker for root privilege escalation, Qualys warned on Monday.

Linux and other Unix-like operating systems are affected by a type of vulnerability that can be exploited by an attacker for root privilege escalation, Qualys warned on Monday.

The flaw, dubbed Stack Clash, is a memory management issue in Linux, OpenBSD, NetBSD, FreeBSD and Solaris on i386 and amd64 architectures. Affected Linux distributions include Red Hat, Debian, Ubuntu, SUSE, CentOS and Gentoo. Other operating systems and architectures could also be vulnerable.

The vulnerability is related to the memory region known as the stack, which grows automatically if an application requires more memory. The problem is that if the stack memory region grows too much, it can get too close to another region, which can result in the application confusing these regions.

This type of flaw, which attackers can exploit to overwrite the stack with another memory region by triggering a clash, has been known since 2005. After it was exploited again in 2010 (CVE-2010-2240), a protection called “stack guard page” was added to the Linux kernel to prevent stack overflow attacks. The stack guard page serves as a divider between a stack memory region and other regions.

However, researchers at Qualys discovered that the stack guard page protection can be bypassed and they developed several proof-of-concept (PoC) exploits to demonstrate it. The main Stack Clash vulnerability is tracked as CVE-2017-1000364, but there are several other flaws that are either directly related to it or independently exploitable.

The PoC code developed by Qualys shows how a local attacker can exploit the vulnerability to escalate privileges to root. However, the company believes remote attacks may also be possible against certain applications.

Advertisement. Scroll to continue reading.

The PoC exploits will only be made public after users have had a chance to patch their systems. Technical details on Stack Clash have been made available by both Qualys and Grsecurity.

The developers of the affected operating systems have started releasing fixes and users have been advised to patch their installations. As a workaround, the hard RLIMIT_STACK and RLIMIT_AS resources of local users and remote services can be set to low values, but experts warned that it may be possible to bypass this mitigation.

Qualys recently reported finding a vulnerability that can be exploited by Sudo users on SELinux-enabled systems for root privilege escalation. The company pointed out that a combination of the Sudo flaw with the Stack Clash allows any local user (not just Sudo users) to escalate privileges on any affected Linux system (not just systems with SELinux enabled).

Related: Google Researcher Details Linux Kernel Exploit

Related: Linux Kernel Flaw Disclosed at Pwn2Own Patched

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Jazz has named Sean Robinson, Rickie Goyal, Danielle Guetta, Shani Nago, and Lior Magram as VPs and Michael Calev as COO.

AJ Shipley has been appointed Chief Product Officer at CrowdStrike.

Brinqa has named Ron Dovich as Chief AI and Automation Officer, David Allen as CTO, Steve Biagioni as CFO, and James Walta as VP of Product.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.