Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 209602 - kernel 2.6.17 - 2.6.24.1 splice: missing user pointer access verification
Summary: kernel 2.6.17 - 2.6.24.1 splice: missing user pointer access verification
Status: RESOLVED DUPLICATE of bug 209460
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] Core system (show other bugs)
Hardware: All Linux
: High blocker (vote)
Assignee: Gentoo Linux bug wranglers
URL: http://bugs.debian.org/cgi-bin/bugrep...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2008-02-10 21:00 UTC by Janusz
Modified: 2008-02-10 21:02 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Janusz 2008-02-10 21:00:27 UTC
"There is a security hole in all versions of linux-2.6 distributed by
Debian, including Etch's kernel."

This is taken from above Debian bugzilla. I confirm it on:

- vanilla 2.6.24.1
- gentoo-sources 2.6.24

both on x86_64. I failed to confirm on vanilla 2.6.23.8 on i586.


Reproducible: Always

Steps to Reproduce:
1.use
2.the exploit
3. included in Debian report! If it disappears for some reasons I can send it to you.

Actual Results:  
System took over by local user.

Expected Results:  
Total disaster. 

I'm waiting for a patch, any local user accounts should be disabled.
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2008-02-10 21:02:23 UTC

*** This bug has been marked as a duplicate of bug 209460 ***