Posted Mar 7, 2011 23:02 UTC (Mon) by jake (editor, #205)
[Link]
> Just that the attacker can use a bit of non-swappable memory by
> loading random modules?
No, the idea is that there may be kernel modules with vulnerabilities that aren't normally loaded, which might make an admin somewhat lax about updating them. If an attacker can load arbitrary modules (even just those in the approved /lib/modules location), it increases the attack surface of the running kernel.
jake
Capabilities for loading network modules
Posted Mar 8, 2011 7:38 UTC (Tue) by rwmj (subscriber, #5474)
[Link]