fixed in v2.6.31.1, also caught by StackProtector
Posted Sep 26, 2009 13:45 UTC (Sat) by
mingo (subscriber, #31122)
In reply to:
fixed in v2.6.31.1, also caught by StackProtector by spender
Parent article:
Kernel release status
Did you have any proof for that one? That SSP stops exploitation of a vuln that doesn't even involve overwriting a return address?
Indeed, i was wrong about that in the changelog, mea culpa. StackProtector has its place, but it would not have stopped the vmsplice exploit.
Thanks,
Ingo
(
Log in to post comments)