REDHAT-BUG-2055499: Medium severity red hat kernel-devel vulnerability
In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approximately 2003 (e.g., with GCC 3.2.2 and Linux kernel 2.4.20). This can cause execution of bytes located in supposedly non-executable regions of a file.
https://github.com/torvalds/linux/blob/1c33bb0507508af24fd754dd7123bd8e997fab2f/arch/x86/include/asm/elf.h#L281-L294 https://github.com/x0reaxeax/exec-prot-bypass
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2055499?
The severity of REDHAT-BUG-2055499 is classified as high due to the potential for execution of arbitrary code in non-executable regions.
How do I fix REDHAT-BUG-2055499?
To fix REDHAT-BUG-2055499, update the Linux kernel to a version beyond 5.16.10 where the vulnerability has been addressed.
What are the affected software versions for REDHAT-BUG-2055499?
The affected software versions for REDHAT-BUG-2055499 include the Linux kernel up to version 5.16.10.
What causes the vulnerability in REDHAT-BUG-2055499?
The vulnerability in REDHAT-BUG-2055499 is caused by certain binary files having the exec-all attribute, allowing execution of data in non-executable memory regions.
Can REDHAT-BUG-2055499 be exploited remotely?
Yes, REDHAT-BUG-2055499 can potentially be exploited remotely if an attacker is able to execute malicious code by leveraging the vulnerability.