One possible SELinux trick
Posted Feb 14, 2008 15:06 UTC (Thu) by
corbet (editor, #1)
In reply to:
vmsplice(): the making of a local root exploit by dale77
Parent article:
vmsplice(): the making of a local root exploit
I just ran across this posting from James Morris on how SELinux (in recent kernels) can block the mapping of memory into very low addresses - a feature which would have defeated this particular exploit.
(
Log in to post comments)