User: Password:
|
|
Subscribe / Log in / New account

Kernel security, year to date

Kernel security, year to date

Posted Sep 18, 2008 7:10 UTC (Thu) by adobriyan (guest, #30858)
In reply to: Kernel security, year to date by spender
Parent article: Kernel security, year to date

> CVE-2008-2365 core DOS Red Hat utrace race
> If you go and look at the bugzilla entry for it:
> https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-2365
> Sitting right there in the OOPS report is everything you need to know:
> RIP = 0, hence trivial arbitrary code execution from Linux 2.6.9 to
> 2.6.25, and not a "DoS".

Sigh...

Those very attentive security researchers and accurate CVE database.

This particular bug was relevant to only kernels patched with utrace.

Only utrace kernels, nothing more.

Mainline was never affected.


(Log in to post comments)


Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds