Stack Clash Linux vulnerability
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Qualys researchers have developed seven exploits and seven proofs of concept for this weakness. Patches are available for all known affected versions.
Each program running on a computer uses a special memory region called the stack. This memory region is special because it grows automatically when the program needs more stack memory. But if it grows too much and gets too close to another memory region, the program may confuse the stack with the other memory region. An attacker can exploit this confusion to overwrite the stack with the other memory region, or the other way around.
The primary vulnerability exploitable by Stack Clash is CVE-2017-1000364
"An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects Linux Kernel versions 4.11.5 and earlier (the stackguard page was introduced in 2010)."
Secondary vulnerabilities exploited includes CVE-2017-1000366 and CVE-2017-1000367
Remediation steps
| Type | Step |
|---|---|
|
Patch to to your vendors advisories SUSE (Document ID:7020973) Red Hat Debian Ubuntu Oracle Solaris |
CVE Vulnerabilities
Last edited: 17 February 2020 11:39 am