Security Vulnerabilities in the ata(7D) Disk Driver May Lead to a Denial of Service Condition



Category :Security
Release Phase :Resolved
Product :Solaris 9 Operating System
Solaris 10 Operating System
Solaris 8 Operating System  
Bug Id :6433123, 6433124  
Date of Resolved Release :21-AUG-2007 


Impact

Security vulnerabilities in certain ioctl(2) functions in the ata(7D) disk driver may allow a local unprivileged user to panic the system, causing a Denial of Service (DoS) condition.


Contributing Factors

These issues can occur in the following releases:

x86 Platform

Notes:

  1. The SPARC platform is not affected by these issues.
  2. These issues only affect x86 systems which have ATA disks installed.
  3. Bug 6433123 concerns two affected ioctls which impact Solaris 8,9 and 10, while Bug 6433124 concerns one additional ioctl which only impacts Solaris 10.

To determine if the ata(7D) kernel module is in use, the following command can be run:

    % modinfo | grep -w ata

Symptoms

Should the described issues occur, the system may panic and generate a stack trace similar to one of the following:

32 bit i386 system:

    ata_disk_ioctl+0x16f()
    dadk_ioctl+0x1d7()
    cmdkioctl+0x361()
    cdev_ioctl+0x2b()
    spec_ioctl+0x62()
    fop_ioctl+0x24()
    ioctl+0x199()
    sys_sysenter+0x101()

64 bit i386 system:

    ata_disk_ioctl+0x14c()
    dadk_ioctl+0x225()
    cmdkioctl+0x1d8()
    cdev_ioctl+0x1d()
    spec_ioctl+0x50()
    fop_ioctl+0x25()
    ioctl+0xac()
    sys_syscall32+0x101()

Workaround

There is no workaround for these issues. Please see the Resolution section below.


Resolution

These issues are addressed in the following releases:

x86 Platform






Attachments
This solution has no attachment

 
 
Login Required

You must login and have a valid contract to access Sun's Premium content which includes:

  • Sun Alerts
  • Bugs
  • Patches
  • Solutions
  • White Papers
  • Documentation
  • Support Knowledge

Login Required

You must login and have a valid contract to access Sun's contracted features

Access Legend:

(Login to access)   Sun Contracted Content
(Login to access)   Sun Contracted Feature

Please make use of SunSolve Feedback application by selecting the floating [+] to provide feedback about this specific document.

Search

Article Details
Article ID : 200606
Article Type : Sun Alert
Last reviewed : 2007-08-21
Audience : PUBLIC
Keywords :
Provide feedback  (help)
Page Tools
»  Print This Page
»  Email This Article
»  Bookmark This Article