Re: [stable] [PATCH] kernel 2.6.24.1 still vulnerable to the vmsplice local root exploit

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Greg KH
Date: Sunday, February 10, 2008 - 10:05 am

On Sun, Feb 10, 2008 at 02:02:27PM +0100, Oliver Pinter wrote:

No, this is a different CVE, as it is a different problem from the
original 09 and 10 report.

It has been given CVE-2008-0600 to address this issue (09 and 10 only
affect .23 and .24 kernels, and have been fixed.)


Hm, perhaps we should just properly check the len field instead?  That's
what is being overflowed here...

thanks,

greg k-h
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [stable] [PATCH] kernel 2.6.24.1 still vulnerable to t ..., Greg KH, (Sun Feb 10, 10:05 am)