LWN.net Logo

Linux 2.6.30 exploit posted

Linux 2.6.30 exploit posted
[Security] Posted Jul 17, 2009 13:30 UTC (Fri) by corbet

Brad Spengler has posted an exploit for a previously unknown vulnerability in the 2.6.30 kernel. "I exploit a bug that by looking at the source is unexploitable; I defeat the null ptr dereference protection in the kernel on both systems with SELinux and those without. I proceed to disable SELinux/AppArmor/LSM/auditing." This ISC diary entry describes how it works; it appears to be a GCC bug in the end. [Update: the "GCC bug" claim was a bit premature; it's a clear kernel bug.]

Full Story (comments: 157)

Copyright © 2009, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds