login
Header Space

 
 

Re: [stable] [PATCH] kernel 2.6.24.1 still vulnerable to the vmsplice local root exploit

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Oliver Pinter <oliver.pntr@...>
Cc: Bastian Blank <bastian@...>, Niki Denev <ndenev@...>, Willy Tarreau <w@...>, <linux-kernel@...>, <jens.axboe@...>, <stable@...>
Date: Sunday, February 10, 2008 - 1:05 pm

On Sun, Feb 10, 2008 at 02:02:27PM +0100, Oliver Pinter wrote:

No, this is a different CVE, as it is a different problem from the
original 09 and 10 report.

It has been given CVE-2008-0600 to address this issue (09 and 10 only
affect .23 and .24 kernels, and have been fixed.)


Hm, perhaps we should just properly check the len field instead?  That's
what is being overflowed here...

thanks,

greg k-h
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [stable] [PATCH] kernel 2.6.24.1 still vulnerable to the..., Greg KH, (Sun Feb 10, 1:05 pm)
speck-geostationary