In the Linux kernel, the following vulnerability has been resolved:
perf/core: Fix unconditional security_locked_down() call
Currently, the lockdown state is queried unconditionally, even though its result is used only if the PERF_SAMPLE_REGS_INTR bit is set in attr.sample_type. While that doesn't matter in case of the Lockdown LSM, it causes trouble with the SELinux's lockdown hook implementation.
SELinux implements the locked_down hook with a check whether the current task's type has the corresponding "lockdown" class permission ("integrity" or "confidentiality") allowed in the policy. This means that calling the hook when the access control decision would be ignored generates a bogus permission check and audit record.
Fix this by checking sample_type first and only calling the hook when its result would be honored.
CVSS Details
- CVSS 3.1 Base Score: 3.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernelUpgrade kernel-headersUpgrade perf-debuginfoUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-tools-develUpgrade kernel-toolsUpgrade perfUpgrade python-perf-debuginfoUpgrade kernel-tools-debuginfoUpgrade bpftoolUpgrade bpftool-debuginfoUpgrade python-perfUpgrade kernel-develUpgrade kernel-debuginfoUpgrade kernel-debuginfo-common-x86_64 | Apr 26, 2024 | Feb 27, 2024 |
| Debian | — | Upgrade linux | Jul 30, 2024 | Feb 27, 2024 |
| Suse | — | Upgrade kernel-defaultUpgrade kernel-macrosUpgrade kernel-docsUpgrade kernel-symsUpgrade kernel-obs-buildUpgrade reiserfs-kmp-defaultUpgrade kernel-64kb-develUpgrade kernel-default-baseUpgrade kernel-preemptUpgrade kernel-sourceUpgrade kernel-zfcpdumpUpgrade kernel-default-develUpgrade kernel-develUpgrade kernel-64kbUpgrade kernel-preempt-devel | Aug 9, 2024 | Feb 27, 2024 |
| Ubuntu | — | Upgrade linux-gkeopUpgrade linux-oracle-5.4Upgrade linux-hwe-5.4Upgrade linux-fipsUpgrade linux-aws-5.4Upgrade linux-azure-fipsUpgrade linux-kvmUpgrade linux-oracleUpgrade linux-raspiUpgrade linux-gcpUpgrade linux-gcp-5.4Upgrade linux-aws-fipsUpgrade linuxUpgrade linux-awsUpgrade linux-raspi-5.4Upgrade linux-bluefieldUpgrade linux-azureUpgrade linux-gcp-fipsUpgrade linux-azure-5.4 | Nov 19, 2024 | Feb 27, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub