<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Critical Linux kernel vmsplice security issues</title>
	<atom:link href="http://www.reactivated.net/weblog/archives/2008/02/critical-linux-kernel-vmsplice-security-issues/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.reactivated.net/weblog/archives/2008/02/critical-linux-kernel-vmsplice-security-issues/</link>
	<description>they got a skin and they put me in</description>
	<pubDate>Fri, 29 Aug 2008 06:01:32 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: EpildtautLiat</title>
		<link>http://www.reactivated.net/weblog/archives/2008/02/critical-linux-kernel-vmsplice-security-issues/#comment-16890</link>
		<dc:creator>EpildtautLiat</dc:creator>
		<pubDate>Mon, 05 May 2008 19:33:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.reactivated.net/weblog/archives/2008/02/critical-linux-kernel-vmsplice-security-issues/#comment-16890</guid>
		<description>"How many people work here?"
	"Oh, about half."

 
---------------------------------------------------------------------------------------------------- 
http://ebloggy.com/nolanphillipszc</description>
		<content:encoded><![CDATA[<p>&#8220;How many people work here?&#8221;<br />
	&#8220;Oh, about half.&#8221;</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
<a href="http://ebloggy.com/nolanphillipszc" rel="nofollow">http://ebloggy.com/nolanphillipszc</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DamionKutaeff</title>
		<link>http://www.reactivated.net/weblog/archives/2008/02/critical-linux-kernel-vmsplice-security-issues/#comment-16703</link>
		<dc:creator>DamionKutaeff</dc:creator>
		<pubDate>Sun, 23 Mar 2008 07:27:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.reactivated.net/weblog/archives/2008/02/critical-linux-kernel-vmsplice-security-issues/#comment-16703</guid>
		<description>Hello everybody, my name is Damion, and I'm glad to join your conmunity, 
and wish to assit as far as possible.</description>
		<content:encoded><![CDATA[<p>Hello everybody, my name is Damion, and I&#8217;m glad to join your conmunity,<br />
and wish to assit as far as possible.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kerin Millar</title>
		<link>http://www.reactivated.net/weblog/archives/2008/02/critical-linux-kernel-vmsplice-security-issues/#comment-16641</link>
		<dc:creator>Kerin Millar</dc:creator>
		<pubDate>Wed, 13 Feb 2008 20:50:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.reactivated.net/weblog/archives/2008/02/critical-linux-kernel-vmsplice-security-issues/#comment-16641</guid>
		<description>&#62; #  KingTaco Says:
&#62; February 11th, 2008 at 6:54 am
&#62; 
&#62; For the record, grsec/pax seems to be immune from this bug on a wide array of tested machines.

As far as I'm aware the attack only fails to achieve its intended goal if PAX_MEMORY_UDEREF is enabled (which is not supported on x86_64 arch). Even then, the PaX author has warned that stack corruption can occur leading to strange behaviour or crashes later. So let us not be lulled into a false sense of security. Hardened kernel users should upgrade to 2.6.23-r7 which contains the appropriate fixes.</description>
		<content:encoded><![CDATA[<p>&gt; #  KingTaco Says:<br />
&gt; February 11th, 2008 at 6:54 am<br />
&gt;<br />
&gt; For the record, grsec/pax seems to be immune from this bug on a wide array of tested machines.</p>
<p>As far as I&#8217;m aware the attack only fails to achieve its intended goal if PAX_MEMORY_UDEREF is enabled (which is not supported on x86_64 arch). Even then, the PaX author has warned that stack corruption can occur leading to strange behaviour or crashes later. So let us not be lulled into a false sense of security. Hardened kernel users should upgrade to 2.6.23-r7 which contains the appropriate fixes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Divide and Conquer &#187; Blog Archive &#187; The vmsplice local root exploit</title>
		<link>http://www.reactivated.net/weblog/archives/2008/02/critical-linux-kernel-vmsplice-security-issues/#comment-16636</link>
		<dc:creator>Divide and Conquer &#187; Blog Archive &#187; The vmsplice local root exploit</dc:creator>
		<pubDate>Tue, 12 Feb 2008 21:17:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.reactivated.net/weblog/archives/2008/02/critical-linux-kernel-vmsplice-security-issues/#comment-16636</guid>
		<description>[...] are some Critical Linux kernel vmsplice security issues that hopefully have been patched properly. Fortunately the kernel on this server is too old to be [...]</description>
		<content:encoded><![CDATA[<p>[...] are some Critical Linux kernel vmsplice security issues that hopefully have been patched properly. Fortunately the kernel on this server is too old to be [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: devBLOG! &#187; Analysis of the two recent Linux 2.6 local exploits (vmsplice)</title>
		<link>http://www.reactivated.net/weblog/archives/2008/02/critical-linux-kernel-vmsplice-security-issues/#comment-16624</link>
		<dc:creator>devBLOG! &#187; Analysis of the two recent Linux 2.6 local exploits (vmsplice)</dc:creator>
		<pubDate>Mon, 11 Feb 2008 20:59:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.reactivated.net/weblog/archives/2008/02/critical-linux-kernel-vmsplice-security-issues/#comment-16624</guid>
		<description>[...] started writting a summary of the two recent Linux 2.6 locals but then found Daniel Drake weblog - he&#8217;s done an excellent job of pulling all the relevant bits [...]</description>
		<content:encoded><![CDATA[<p>[...] started writting a summary of the two recent Linux 2.6 locals but then found Daniel Drake weblog - he&#8217;s done an excellent job of pulling all the relevant bits [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Local Root Exploit &#124; USmith Blog</title>
		<link>http://www.reactivated.net/weblog/archives/2008/02/critical-linux-kernel-vmsplice-security-issues/#comment-16623</link>
		<dc:creator>Local Root Exploit &#124; USmith Blog</dc:creator>
		<pubDate>Mon, 11 Feb 2008 19:24:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.reactivated.net/weblog/archives/2008/02/critical-linux-kernel-vmsplice-security-issues/#comment-16623</guid>
		<description>[...] den anderen Hosts sah es aber leider nicht so gut aus. Daniel Drake und Tobi hatten es ja die L&#252;cke schon gut beschrieben. Der Exploit ist, wenn man einen lokalen [...]</description>
		<content:encoded><![CDATA[<p>[...] den anderen Hosts sah es aber leider nicht so gut aus. Daniel Drake und Tobi hatten es ja die L&#252;cke schon gut beschrieben. Der Exploit ist, wenn man einen lokalen [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel Drake</title>
		<link>http://www.reactivated.net/weblog/archives/2008/02/critical-linux-kernel-vmsplice-security-issues/#comment-16622</link>
		<dc:creator>Daniel Drake</dc:creator>
		<pubDate>Mon, 11 Feb 2008 17:30:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.reactivated.net/weblog/archives/2008/02/critical-linux-kernel-vmsplice-security-issues/#comment-16622</guid>
		<description>That's not a configuration option. And, I haven't tried myself, but I've seen a few reports that that runtime hack can also cause the kernel to crash (not surprising given that the exploit does the same sometimes)</description>
		<content:encoded><![CDATA[<p>That&#8217;s not a configuration option. And, I haven&#8217;t tried myself, but I&#8217;ve seen a few reports that that runtime hack can also cause the kernel to crash (not surprising given that the exploit does the same sometimes)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pawel</title>
		<link>http://www.reactivated.net/weblog/archives/2008/02/critical-linux-kernel-vmsplice-security-issues/#comment-16621</link>
		<dc:creator>Pawel</dc:creator>
		<pubDate>Mon, 11 Feb 2008 16:31:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.reactivated.net/weblog/archives/2008/02/critical-linux-kernel-vmsplice-security-issues/#comment-16621</guid>
		<description>"there is no configuration option to exclude vmsplice" 

Really?

$ ./disable-vmsplice-if-exploitable
PAGE_SIZE: 4096
-----------------------------------
 Linux vmsplice Local Root Exploit
 By qaaz
-----------------------------------
[+] mmap: 0x0 .. 0x1000
[+] page: 0x0
[+] page: 0x20
[+] mmap: 0x4000 .. 0x5000
[+] page: 0x4000
[+] page: 0x4020
[+] mmap: 0x1000 .. 0x2000
[+] page: 0x1000
[+] mmap: 0xb7db6000 .. 0xb7de8000
[-] vmsplice: Function not implemented

$ uname -a
Linux xxxx 2.6.24-gentoo #8 SMP PREEMPT Fri Feb 8 15:34:20 CET 2008 i686 Intel(R) Core(TM)2 Duo CPU     T7700  @ 2.40GHz GenuineIntel GNU/Linux</description>
		<content:encoded><![CDATA[<p>&#8220;there is no configuration option to exclude vmsplice&#8221; </p>
<p>Really?</p>
<p>$ ./disable-vmsplice-if-exploitable<br />
PAGE_SIZE: 4096<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
 Linux vmsplice Local Root Exploit<br />
 By qaaz<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
[+] mmap: 0&#215;0 .. 0&#215;1000<br />
[+] page: 0&#215;0<br />
[+] page: 0&#215;20<br />
[+] mmap: 0&#215;4000 .. 0&#215;5000<br />
[+] page: 0&#215;4000<br />
[+] page: 0&#215;4020<br />
[+] mmap: 0&#215;1000 .. 0&#215;2000<br />
[+] page: 0&#215;1000<br />
[+] mmap: 0xb7db6000 .. 0xb7de8000<br />
[-] vmsplice: Function not implemented</p>
<p>$ uname -a<br />
Linux xxxx 2.6.24-gentoo #8 SMP PREEMPT Fri Feb 8 15:34:20 CET 2008 i686 Intel(R) Core(TM)2 Duo CPU     T7700  @ 2.40GHz GenuineIntel GNU/Linux</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: grml development blog</title>
		<link>http://www.reactivated.net/weblog/archives/2008/02/critical-linux-kernel-vmsplice-security-issues/#comment-16619</link>
		<dc:creator>grml development blog</dc:creator>
		<pubDate>Mon, 11 Feb 2008 12:25:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.reactivated.net/weblog/archives/2008/02/critical-linux-kernel-vmsplice-security-issues/#comment-16619</guid>
		<description>&lt;strong&gt;kernel 2.6.23-grml addressing CVE-2008-0009/10 available...&lt;/strong&gt;

Kernel 2.6.23-grml.06 is available in the grml repository. It includes latest stable patch 2.6.23.16 which addresses the well known root exploits from CVE-2008-0009/10 (see bugzilla #9924 and debian BTS #464953 and dsd's detailed explanation for furth...</description>
		<content:encoded><![CDATA[<p><strong>kernel 2.6.23-grml addressing CVE-2008-0009/10 available&#8230;</strong></p>
<p>Kernel 2.6.23-grml.06 is available in the grml repository. It includes latest stable patch 2.6.23.16 which addresses the well known root exploits from CVE-2008-0009/10 (see bugzilla #9924 and debian BTS #464953 and dsd&#8217;s detailed explanation for furth&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: vivo</title>
		<link>http://www.reactivated.net/weblog/archives/2008/02/critical-linux-kernel-vmsplice-security-issues/#comment-16618</link>
		<dc:creator>vivo</dc:creator>
		<pubDate>Mon, 11 Feb 2008 10:05:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.reactivated.net/weblog/archives/2008/02/critical-linux-kernel-vmsplice-security-issues/#comment-16618</guid>
		<description>http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.2 should fix CVE-2008-0600.</description>
		<content:encoded><![CDATA[<p><a href="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.2" rel="nofollow">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.2</a> should fix CVE-2008-0600.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
