LWN.net Logo

kernel: local root privilege escalation

Package(s):linux-2.6 CVE #(s):CVE-2008-0010 CVE-2008-0600
Created:February 11, 2008 Updated:June 23, 2008
Description:

From the Debian advisory:

The vmsplice system call did not properly verify address arguments passed by user space processes, which allowed local attackers to overwrite arbitrary kernel memory, gaining root privileges (CVE-2008-0010, CVE-2008-0600).

Alerts:
SuSE SUSE-SA:2008:030 2008-06-20
Fedora FEDORA-2008-4043 2008-05-17
Fedora FEDORA-2008-3873 2008-05-14
SuSE SUSE-SA:2008:013 2008-03-06
Ubuntu USN-577-1 2008-02-12
Slackware SSA:2008-042-01 2008-02-13
rPath rPSA-2008-0052-1 2008-02-12
Red Hat RHSA-2008:0129-01 2008-02-12
Fedora FEDORA-2008-1433 2008-02-13
Fedora FEDORA-2008-1629 2008-02-13
Debian DSA-1494-2 2008-02-12
SuSE SUSE-SA:2008:007 2008-02-12
Mandriva MDVSA-2008:044 2008-02-12
Mandriva MDVSA-2008:043 2007-02-11
Debian DSA-1494-1 2008-02-11
Fedora FEDORA-2008-1423 2008-02-11
Fedora FEDORA-2008-1422 2008-02-11

(Log in to post comments)

kernel: local root privilege escalation

Posted Feb 13, 2008 10:04 UTC (Wed) by mjcox@redhat.com (subscriber, #31775) [Link]

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds