Exploitation Summary
CVE-2017-1000253 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added September 9, 2024, with confirmed use in ransomware campaigns. EIP tracks 3 public exploits from researchers including Qualys Corporation, RicterZ, sxlmnwb.
AI-analyzed exploit summary This exploit targets a local privilege escalation vulnerability in the Linux kernel (CVE-2017-1000253) affecting CentOS-7 kernel versions 3.10.0-514.21.2.el7.x86_64 and 3.10.0-514.26.1.el7.x86_64. It leverages a memory management flaw to gain root privileges by manipulating the stack guard gap.
Description
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a security threat. With CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE enabled, and a normal top-down address allocation strategy, load_elf_binary() will attempt to map a PIE binary into an address range immediately below mm->mmap_base. Unfortunately, load_elf_ binary() does not take account of the need to allocate sufficient space for the entire binary which means that, while the first PT_LOAD segment is mapped below mm->mmap_base, the subsequent PT_LOAD segment(s) end up being mapped above mm->mmap_base into the are that is supposed to be the "gap" between the stack and the binary.
Exploits (3)
This exploit targets a local privilege escalation vulnerability in the Linux kernel (CVE-2017-1000253) affecting CentOS-7 kernel versions 3.10.0-514.21.2.el7.x86_64 and 3.10.0-514.26.1.el7.x86_64. It leverages a memory management flaw to gain root privileges by manipulating the stack guard gap.
This repository contains a functional exploit for CVE-2017-1000253, a stack clash vulnerability in the Linux kernel affecting CentOS-7 kernel versions 3.10.0-514.21.2.el7.x86_64 and 3.10.0-514.26.1.el7.x86_64. The exploit leverages the stack clash technique to achieve local privilege escalation (LPE) by manipulating stack memory and executing a rootshell payload.
This repository contains a functional exploit for CVE-2017-1000253, a local privilege escalation vulnerability in the Linux kernel affecting CentOS-7 versions 3.10.0-514.21.2.el7.x86_64 and 3.10.0-514.26.1.el7.x86_64. The exploit leverages a memory corruption issue in the kernel's handling of PIE (Position Independent Executable) binaries to gain root privileges.
References (14)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H