Skip to main content

Stack Clash Linux vulnerability

The Stack Clash is a vulnerability in the memory management in the affected platforms. It can be exploited by attackers to corrupt memory and execute arbitrary code.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

The Stack Clash is a vulnerability in the memory management in the affected platforms. It can be exploited by attackers to corrupt memory and execute arbitrary code.

Affected platforms

The following platforms are known to be affected:

Threat details

Qualys researchers have developed seven exploits and seven proofs of concept for this weakness. Patches are available for all known affected versions.

Each program running on a computer uses a special memory region called the stack. This memory region is special because it grows automatically when the program needs more stack memory. But if it grows too much and gets too close to another memory region, the program may confuse the stack with the other memory region. An attacker can exploit this confusion to overwrite the stack with the other memory region, or the other way around.

The primary vulnerability exploitable by  Stack Clash is CVE-2017-1000364
"An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects Linux Kernel versions 4.11.5 and earlier (the stackguard page was introduced in 2010)."

Secondary vulnerabilities exploited includes CVE-2017-1000366 and CVE-2017-1000367



CVE Vulnerabilities

Last edited: 17 February 2020 11:39 am