[Gloucs] Linux kernel vulnerability

Glyn Davies glynd at walmore.com
Sun Feb 10 23:24:51 GMT 2008


The LUGmaster list had a few posts concerning a local user vulnerability 
in kernels since 2.6.17. This appears to have surfaced a few days ago.

I don't have user friendly details but to quote from the posting, "it is 
currently listed on http://isc.sans.org/newssummary.html as "Linux 
Kernel 2.6.17 - 2.6.24.1 vmsplice Local Root Exploit"

I guess this is the same but not sure.
http://www.securityfocus.com/bid/27704

This has been quot4ed as a "cool fix" on the LUGmaster list.  I know not 
if it is.
http://article.gmane.org/gmane.linux.debian.devel.kernel/35305

Thought I'd post to the list as I expect some of you look after boxes 
with users on.

-- 
Best Regards
Glyn Davies




More information about the gloucs mailing list