Local root exploit in kernel 2.6.17 - 2.6.24 (vmsplice)
Bug #190587 reported by
Hirvinen
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Linux |
Fix Released
|
High
|
|||
CentOS |
Fix Released
|
Critical
|
|||
Debian |
Fix Released
|
Unknown
|
|||
Gentoo Linux |
Fix Released
|
Undecided
|
Unassigned | ||
Mandriva |
Fix Released
|
Critical
|
|||
Ubuntu |
Fix Released
|
Undecided
|
Unassigned | ||
gplcver (Ubuntu) |
Invalid
|
Undecided
|
Unassigned | ||
linux (Fedora) |
Fix Released
|
Critical
|
|||
linux (Ubuntu) |
Fix Released
|
High
|
Unassigned | ||
linux-source-2.6.15 (Ubuntu) |
Invalid
|
Undecided
|
Unassigned | ||
linux-source-2.6.17 (Ubuntu) |
Fix Released
|
High
|
Jamie Strandboge | ||
linux-source-2.6.20 (Ubuntu) |
Fix Released
|
High
|
Jamie Strandboge | ||
linux-source-2.6.22 (Ubuntu) |
Fix Released
|
High
|
Jamie Strandboge |
Bug Description
https:/
Related branches
Changed in linux: | |
status: | Unknown → Fix Committed |
Changed in linux: | |
status: | Fix Committed → Fix Released |
Changed in linux-source-2.6.22: | |
status: | Fix Committed → Fix Released |
Changed in linux-source-2.6.17: | |
assignee: | keescook → jamie-strandboge |
status: | Fix Committed → Fix Released |
Changed in linux-source-2.6.20: | |
assignee: | keescook → jamie-strandboge |
status: | Fix Committed → Fix Released |
Changed in linux-source-2.6.22: | |
assignee: | keescook → jamie-strandboge |
Changed in linux: | |
status: | Fix Committed → Fix Released |
Changed in linux-source-2.6.24: | |
status: | New → Fix Released |
Changed in gplcver: | |
status: | New → Invalid |
Changed in linux: | |
status: | Unknown → Fix Released |
Changed in linux: | |
importance: | Unknown → High |
Changed in mandriva: | |
importance: | Unknown → Critical |
Changed in linux (Fedora): | |
importance: | Unknown → Critical |
Changed in centos: | |
importance: | Unknown → Critical |
Latest working kernel version: milw0rm. com/exploits/ 5093 milw0rm. com/exploits/ 5092
Earliest failing kernel version: 2.6.17
Distribution: Gentoo
Hardware Environment:
Software Environment:
Problem Description:
Two root exploits have been reported:
http://
http://
Both exploits cause kernel Oops or (randomly) give root privilegies to the user.
Here is the same bug reported in gentoo bugzilla: bugs.gentoo. org/show_ bug.cgi? id=209460
http://
Steps to reproduce:
Compile and run the exploit.