All of lore.kernel.org
 help / color / mirror / Atom feed
* kernel 2.6.24.1 still vulnerable to the vmsplice local root exploit
@ 2008-02-10  6:04 Niki Denev
  2008-02-10  6:32 ` Willy Tarreau
  0 siblings, 1 reply; 15+ messages in thread
From: Niki Denev @ 2008-02-10  6:04 UTC (permalink / raw)
  To: linux-kernel

Hi,

As the subject says the 2.6.24.1 is still vulnerable to the vmsplice
local root exploit.

[opa@test tmp]$ uname -a
Linux tester 2.6.24.1 #1 Sun Feb 10 00:06:49 EST 2008 i686 unknown
[opa@test tmp]$ ./vms

-----------------------------------
 Linux vmsplice Local Root Exploit
 By qaaz
-----------------------------------
[+] mmap: 0x0 .. 0x1000
[+] page: 0x0
[+] page: 0x20
[+] mmap: 0x4000 .. 0x5000
[+] page: 0x4000
[+] page: 0x4020
[+] mmap: 0x1000 .. 0x2000
[+] page: 0x1000
[+] mmap: 0xb7f56000 .. 0xb7f88000
[+] root
[root@test tmp]#
[root@test tmp]# id
uid=0(root) gid=0(root) groups=2033(opa)
[root@test tmp]# uname -a
Linux test 2.6.24.1 #1 Sun Feb 10 00:06:49 EST 2008 i686 unknown

Is there any known fix/patch for this?

^ permalink raw reply	[flat|nested] 15+ messages in thread

end of thread, other threads:[~2008-02-10 17:48 UTC | newest]

Thread overview: 15+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2008-02-10  6:04 kernel 2.6.24.1 still vulnerable to the vmsplice local root exploit Niki Denev
2008-02-10  6:32 ` Willy Tarreau
2008-02-10  6:38   ` Niki Denev
2008-02-10  9:40     ` [PATCH] " Niki Denev
2008-02-10 12:04       ` Oliver Pinter
2008-02-10 12:22       ` Bastian Blank
2008-02-10 12:39         ` Niki Denev
2008-02-10 12:47           ` Bastian Blank
2008-02-10 12:54             ` Niki Denev
2008-02-10 13:02             ` Oliver Pinter
2008-02-10 17:05               ` [stable] " Greg KH
2008-02-10 17:11                 ` Pekka Enberg
2008-02-10 17:44                 ` Oliver Pinter
2008-02-10 17:48                 ` Oliver Pinter
2008-02-10 13:48         ` Niki Denev

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.