[Hampshire] Linux kernel 2.6.17-2.6.24 root exploit

Top Page

Reply to this message
Author: Tony Whitmore
Date:  
To: Hampshire LUG Discussion List
Subject: [Hampshire] Linux kernel 2.6.17-2.6.24 root exploit
You'll probably see this on lots of news sites, but there's a local root
exploit been discovered in the above kernel versions. This gives any
local user account the chance to gain root privileges on a system.

The suggestions are to disable untrusted local users until a fixed
kernel can be produced* or to use a temporary kernel module to disable
the affected system call.

http://isc.sans.org/newssummary.html

https://tyneside.lug.org.uk/news.php?callmodule=All%20news%20articles&startarticle=0&select=50

The HantsLUG server is not running an affected kernel version.

Tony

* There is a point release of the kernel to address the issue but it's
not clear whether it fully fixes the problem. Any fix will also take
time to make its way into distros.