A privilege escalation flaw in udev
Posted Apr 23, 2009 17:08 UTC (Thu) by jimparis
In reply to: A privilege escalation flaw in udev
Parent article: A privilege escalation flaw in udev
That is not true. Go look at Kay's commit. It adds the SO_PASSCRED option to the socket and adds an explicit check for (cred->uid != 0). As the LWN writeup indicated, 'either patch "alone would be sufficient" to fix the problem'.
And your statement about him being quick to notify others is misleading at best. There has still not been a single posting on the udev mailing list about this problem!
to post comments)