LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 08-19-2010, 01:14 AM   #1
dolphin77
Member
 
Registered: May 2009
Location: Odesa, Ukraine
Distribution: Slackware
Posts: 206

Rep: Reputation: 60
linux kernels-2.6 local root vulnerability


http://theinvisiblethings.blogspot.c...ux-closet.html
http://www.invisiblethingslab.com/re...ry-attacks.pdf

will this affect slackware-13.1?

Maybe new kernel has to be released in /patches ?
 
Old 08-19-2010, 02:47 AM   #2
astrogeek
Moderator
 
Registered: Oct 2008
Distribution: Slackware [64]-X.{0|1|2|37|-current} ::12<=X<=15, FreeBSD_12{.0|.1}
Posts: 6,264
Blog Entries: 24

Rep: Reputation: 4195Reputation: 4195Reputation: 4195Reputation: 4195Reputation: 4195Reputation: 4195Reputation: 4195Reputation: 4195Reputation: 4195Reputation: 4195Reputation: 4195
Quote:
Originally Posted by dolphin77 View Post
http://theinvisiblethings.blogspot.c...ux-closet.html
http://www.invisiblethingslab.com/re...ry-attacks.pdf

will this affect slackware-13.1?

Maybe new kernel has to be released in /patches ?
From the PDF in your second link:

Quote:
The Linux kernel versions that include the commit
320b2b8de12698082609ebbc1a17165727f4c893 from Linus tree
are fixed. Particularly, 2.6.35.2 and 2.6.34.4 are fixed.
That does not seem to include the 2.6.33.4 of SW 13.1.
 
Old 08-19-2010, 03:12 AM   #3
ponce
LQ Guru
 
Registered: Aug 2004
Location: Pisa, Italy
Distribution: Slackware
Posts: 7,098

Rep: Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175
I think we have to wait for the right patches

http://security-tracker.debian.org/t.../CVE-2010-2240

but it should be backportable (who knows which is the older kernel it's able to run on)

https://bugzilla.redhat.com/show_bug.cgi?id=606611

Last edited by ponce; 08-19-2010 at 03:14 AM.
 
Old 08-19-2010, 03:15 AM   #4
astrogeek
Moderator
 
Registered: Oct 2008
Distribution: Slackware [64]-X.{0|1|2|37|-current} ::12<=X<=15, FreeBSD_12{.0|.1}
Posts: 6,264
Blog Entries: 24

Rep: Reputation: 4195Reputation: 4195Reputation: 4195Reputation: 4195Reputation: 4195Reputation: 4195Reputation: 4195Reputation: 4195Reputation: 4195Reputation: 4195Reputation: 4195
Quote:
Originally Posted by ponce View Post
I think we have to wait for the right patches
HA! I built a 2.6.35.2 for one of my SW 13.1 boxes just yesterday... I think I'll do that for all of them now!
 
Old 08-19-2010, 04:34 AM   #5
ponce
LQ Guru
 
Registered: Aug 2004
Location: Pisa, Italy
Distribution: Slackware
Posts: 7,098

Rep: Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175
a friend, kernelOfTruth ( ), pointed me to these (bug introduced by that linus' commit):

https://bugzilla.kernel.org/show_bug.cgi?id=16588

linus committed a potential fix (probably will be included in 2.6.35.3)

http://www.kernel.org/pub/linux/kern...stable-review/

Last edited by ponce; 08-19-2010 at 04:55 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Root vulnerability in DD-WRT free router firmware LXer Syndicated Linux News 0 07-23-2009 01:00 AM
LXer: Root Exploit Vulnerability in Kernel 2.6.30 LXer Syndicated Linux News 0 07-21-2009 08:10 PM
Linux Kernel 2.6 Local Root Exploit by vmsplice? Inuit-Uprising Slackware 9 02-13-2008 09:41 AM
Linux Kernel Vulnerability jeremy Linux - Security 2 03-15-2005 02:03 AM
Easy access to root - vulnerability? Gay R0b0t Linux - Software 5 02-21-2005 08:19 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 07:57 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration