Linux 2.6.30 exploit posted
[Posted July 17, 2009 by corbet]
Linux 2.6.30 exploit posted
[Security] Posted Jul 17, 2009 13:30 UTC (Fri) by corbet
Brad Spengler has posted an exploit for a previously unknown vulnerability
in the 2.6.30 kernel. "I exploit a bug that by looking at the source is unexploitable;
I defeat the null ptr dereference protection in the kernel on
both systems with SELinux and those without.
I proceed to disable SELinux/AppArmor/LSM/auditing." This ISC diary
entry describes how it works; it appears to be a GCC bug in the end.
[Update: the "GCC bug" claim was a bit premature; it's a clear
kernel bug.]
Full Story (comments: 157)