Umbra Wiki weakness weakness/CWE-432
Back to wiki

CWE-432 — Dangerous Signal Handler not Disabled During Sensitive Operations

provenance: imported · CWE: CWE-432

CWE-432: Dangerous Signal Handler not Disabled During Sensitive Operations

MITRE CWE weakness

Kind Weakness
Abstraction Base
Status Draft
Likelihood of exploit

Description

The product uses a signal handler that shares state with other signal handlers, but it does not properly mask or prevent those signal handlers from being invoked while the original signal handler is still running.

During the execution of a signal handler, it can be interrupted by another handler when a different signal is sent. If the two handlers share state - such as global variables - then an attacker can corrupt the state by sending another signal before the first handler has completed execution.

Common consequences

  • Integrity: Modify Application Data

Mitigations

Implementation — Turn off dangerous handlers when performing sensitive operations.

References

  • CWE page: https://cwe.mitre.org/data/definitions/432.html
  • CWE list: https://cwe.mitre.org/data/index.html