HIGH CISA KEV Public exploit Introduced in 2.6.25
binfmt_elf PIEBinary Overflow
CVE-2017-1000253
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.8HIGH
01Description
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a security threat. With CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE enabled, and a normal top-down address allocation strategy, load_elf_binary() will attempt to map a PIE binary into an address range immediately below mm->mmap_base. Unfortunately, load_elf_ binary() does not take account of the need to allocate sufficient space for the entire binary which means that, while the first PT_LOAD segment is mapped below mm->mmap_base, the subsequent PT_LOAD segment(s) end up being mapped above mm->mmap_base into the are that is supposed to be the "gap" between the stack and the binary.
02KernelScan AI Analysis
Risk summary
A local unprivileged user can execute a specially crafted PIE (position-independent executable) binary whose data segment is large enough to overflow the reserved gap between the binary and the stack. On x86_64 this gap is only guaranteed to be 128 MB, so a binary with a larger data segment can have its subsequent load segments mapped directly over the stack, corrupting it. This can lead to arbitrary code execution with kernel-level loading context. The flaw requires only local code execution privileges—no special hardware or network access is needed—and is in the CISA Known Exploited Vulnerabilities catalog.
Vulnerability analysis
When loading a PIE binary, the ELF loader maps the first load segment just below the process's mmap base address but fails to account for the total space needed by all segments combined. As a result, later segments can be placed above the mmap base, landing in the gap reserved between the binary and the stack. On x86_64 that gap is only guaranteed to be 128 MB, so a binary with a data segment larger than that can overwrite the stack during loading, causing memory corruption that is exploitable for privilege escalation. The fix calculates the full mapping size of the binary before placing it, ensuring the loader reserves enough contiguous space below the mmap base for every segment. Any local user who can execute a crafted PIE binary can trigger this; no special privileges, network access, or specific hardware are required.
Exploit availability
KernelScan found public exploit code for this CVE. Open it in the CVE browser to see what we found, where, and how strong the evidence is — that needs a free account with a confirmed email address.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 3.2 | 2.6.25 | 3.2.70 | — |
| 3.4 | 2.6.25 | 3.4.109 | — |
| 3.10 | 2.6.25 | 3.10.77 | — |
| 3.12 | 2.6.25 | 3.12.43 | — |
| 3.14 | 2.6.25 | 3.14.41 | — |
| 3.16 | 2.6.25 | 3.16.35 | — |
| 3.18 | 2.6.25 | 3.18.14 | — |
| 3.19 | 2.6.25 | 3.19.7 | — |
| 4.0 | 2.6.25 | 4.0.2 | — |
| mainline | 2.6.25 | 4.1-rc1 | a87938b2e246 |