Linux Kernel v2.6 Local Root Exploit ( vmsplice ) Found

by Vivek Gite on February 11, 2008 · 4 comments

Linux kernel version from 2.6.17 to 2.6.24.1 all are affected because of vmsplice bug. The exploit code can be used to test if a kernel is vulnerable and it can start a root shell.

=> Debian Bug report logs

=> Fix 1 and Fix 2

Update: See how to apply a patch to kernel source tree.

Featured Articles:

Share this with other sys admins!
Facebook it - Tweet it - Print it -

We're here to help you make the most of sysadmin work. So, subscribe!

{ 4 comments… read them below or add one }

1 Jerod February 11, 2008

What would be helpful would be an explanation of how to apply these fixes to a vulnerable kernel.

Reply

2 goll February 11, 2008

I second that!

Reply

3 Erek Dyskant February 11, 2008

Howdy All,
I have a redhat/Centos RPMs with the upstream kernel patch compiled at http://erek.blumenthals.com/blog/

Reply

4 Peter March 10, 2008

Don’t let this one slide people – patch now.

All distro’s now have updated kernel packages. Apply them. :)

Reply

Leave a Comment

You can use these HTML tags and attributes for your code and commands: <strong> <em> <ol> <li> <u> <ul> <blockquote> <pre> <a href="" title="">
What is 10 + 6 ?
Please leave these two fields as-is:
Are you a human being? Solve the simple math so we know that you are a human and not a bot.




Previous post:

Next post: