[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Kernel bug (time to upgrade!)



On Wed, Mar 28, 2001 at 09:16:45AM -0600, Steven Pritchard wrote:
> There's another security issue with 2.2.18 and earlier.  2.2.19 is
> out, and it fixes the bug.
> 
>     ftp://ftp.luci.org/pub/linux/kernel/v2.2/linux-2.2.19.tar.bz2
>     http://ftp.luci.org/pub/linux/kernel/v2.2/linux-2.2.19.tar.bz2
>     rsync://ftp.luci.org/kernel/v2.2/linux-2.2.19.tar.bz2
> 
> Hopefully the distribution vendors will have kernel updates out soon.

Is this different from the ptrace race condition?

There is a fix for that which disables the ptrace system call, but the
problem occurs upstream of ptrace, so there's not a 100% guarentee that
it can be exploited elsewhere.

Anyhow, I've even been too lazy to install the patch.

-- 
Jordan Bettis <http://www.hafd.org/~jordanb/>
The Unix Philosophy: Do one thing and do it well.
The GNU Philosophy: The Unix Philosophy, for sufficiently large values 
                    of "one".
-
To unsubscribe, send email to majordomo@luci.org with
"unsubscribe luci-discuss" in the body.