LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-18-2010, 04:25 AM   #1
piperts
LQ Newbie
 
Registered: Sep 2010
Location: Australia
Distribution: CentOS and Debian
Posts: 2

Rep: Reputation: 0
Exclamation Kernel exploit on 64-bit operating systems


I've seen the latest exploit for RHEL/CentOS operating systems running 64bit. So far i've temporarily disabled 32bit application execution.

The exploit information: https://access.redhat.com/kb/docs/DOC-40265

I'm running CentOS 5.5 64bit and am wondering if there is a permanent fix available?
 
Old 09-18-2010, 05:06 AM   #2
smoker
Senior Member
 
Registered: Oct 2004
Distribution: Fedora Core 4, 12, 13, 14, 15, 17
Posts: 2,279

Rep: Reputation: 250Reputation: 250Reputation: 250
The page you linked to is only 2 days old. When you next receive any updates, if a fix has been issued it will be part of the updates.
 
Old 09-18-2010, 03:14 PM   #3
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by piperts View Post
I've seen the latest exploit for RHEL/CentOS operating systems running 64bit. So far i've temporarily disabled 32bit application execution.

The exploit information: https://access.redhat.com/kb/docs/DOC-40265

I'm running CentOS 5.5 64bit and am wondering if there is a permanent fix available?
On Ubuntu, we received updated kernel packages which addressed this vulnerability (as well as an additional one) yesterday IIRC, so I would expect Red Hat to be doing the same RSN. So yes, there's a permanent fix but you need to wait for your updated kernel package to arrive unless you want to apply the patch on your own and re-compile your kernel.
 
Old 09-19-2010, 12:58 AM   #4
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
FYI, this issue has made it to Slashdot.

EDIT: BTW, I'm gonna sticky this thread for a few days.

Last edited by win32sux; 09-19-2010 at 01:01 AM.
 
Old 09-19-2010, 04:09 AM   #5
piperts
LQ Newbie
 
Registered: Sep 2010
Location: Australia
Distribution: CentOS and Debian
Posts: 2

Original Poster
Rep: Reputation: 0
Thanks for the advice win32sux and smoker.

Here is the bugzilla report - https://bugzilla.redhat.com/show_bug...=CVE-2010-3081
 
Old 09-20-2010, 12:22 PM   #6
qweasd
Member
 
Registered: May 2010
Posts: 621

Rep: Reputation: Disabled
Anyone else was able to compile this exploit? (Careful, it may be leaving backdoors in RAM.) I cannot because __i386__ is not defined. Note that this CVE-2010-3081 is different from CVE-2010-3301, which is nicely documented and has a working exploit which appears to be clean.
 
Old 09-20-2010, 03:21 PM   #7
beadyallen
Member
 
Registered: Mar 2008
Location: UK
Distribution: Fedora, Gentoo
Posts: 209

Rep: Reputation: 36
Yes, the exploit compiles with one very minor change. Probably against the rules to say what it is, but once compiled it works silently on a fresh Centos 5 installation. We're waiting for the kernel fix. It's quite a serious flaw (especially given the availability of the exploit).
 
Old 09-20-2010, 03:47 PM   #8
smoker
Senior Member
 
Registered: Oct 2004
Distribution: Fedora Core 4, 12, 13, 14, 15, 17
Posts: 2,279

Rep: Reputation: 250Reputation: 250Reputation: 250
Quote:
Originally Posted by qweasd View Post
(Careful, it may be leaving backdoors in RAM.)
Hardly a backdoor really. reboot and it's gone.
 
Old 09-21-2010, 05:17 AM   #9
rsciw
Member
 
Registered: Jan 2009
Location: Essex (UK)
Distribution: Home: Debian/Ubuntu, Work: Ubuntu
Posts: 206

Rep: Reputation: 44
here's the RHN link
https://rhn.redhat.com/errata/RHSA-2010-0704.html
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] linux kernel: 64-bit Compatibility Mode vulns (local root exploit) ponce Slackware 38 09-24-2010 12:49 PM
three operating systems emrkar Linux - Newbie 3 01-24-2010 04:36 PM
two operating systems harbey altai Linux - Newbie 7 05-07-2008 06:11 AM
2 operating systems junkano Linux - Newbie 8 01-24-2007 03:18 PM
Two Operating Systems PEDRO Linux - Software 1 01-28-2001 10:34 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:51 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration