Bug 1015160 - (CVE-2016-6786) VUL-0: CVE-2016-6786 CVE-2016-6787: kernel-source: Possible privilege escalation due to lack of locking around changing event->ctx
(CVE-2016-6786)
VUL-0: CVE-2016-6786 CVE-2016-6787: kernel-source: Possible privilege escalat...
Status: RESOLVED WONTFIX
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Major
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/177441/
CVSSv2:SUSE:CVE-2016-6786:6.2:(AV:L/A...
:
Depends on: CVE-2017-6001
Blocks:
  Show dependency treegraph
 
Reported: 2016-12-12 15:58 UTC by Marcus Meissner
Modified: 2022-03-31 08:09 UTC (History)
8 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2016-12-12 15:58:02 UTC
via rh bugzilla

Possible privilege escalation issue due to lack of mutex locking around places where perf_event::ctx is being changed.

Upstream patch:

https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f63a8daa5812afef4f06c962351687e1ff9ccb2b

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1403842
Comment 1 Marcus Meissner 2016-12-12 16:08:36 UTC
this fix is in 4.0, so only older kernels might be affected.
Comment 2 Swamp Workflow Management 2016-12-12 23:01:26 UTC
bugbot adjusting priority
Comment 3 Mikhail Kasimov 2017-02-16 10:06:41 UTC
See also: boo #1025626 (VUL-0: CVE-2017-6001: kernel-source: Incomplete fix for CVE-2016-6786: perf/core: Fix concurrent sys_perf_event_open() vs. 'move_group' race)
Comment 4 Marcus Meissner 2020-01-20 15:35:20 UTC
Tony?
Comment 5 Tony Jones 2020-02-05 19:01:48 UTC
(In reply to Marcus Meissner from comment #4)
> Tony?

The locking changed between cve-3.12 and 4.0 which has the fix.  

The bug is very vague about what the issue is.  

"There have been a few reported issues wrt. the lack of locking around
changing event->ctx. This patch tries to address those" isn't worth the risk of destabilizing an LTSS branch IMO.
Comment 6 Gabriele Sonnu 2022-03-31 08:08:29 UTC
We have decided to not release update for the still affected codestreams (3.x series) as to not risk destabilizing LTSS branches. Closing as WONTFIX.
Comment 7 Gabriele Sonnu 2022-03-31 08:09:23 UTC
Closing.