Gentoo Archives: gentoo-dev

From: Alan <alan@×××××.org>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Second critical mremap() bug found in all Linux kernels
Date: Wed, 18 Feb 2004 18:37:25
Message-Id: 20040218183745.GE27148@ufies.org
In Reply to: [gentoo-dev] Second critical mremap() bug found in all Linux kernels by Christian Gut
1 On Wed, Feb 18, 2004 at 04:57:23PM +0100, Christian Gut wrote:
2 > damn, again:
3 >
4 > http://bugs.gentoo.org/show_bug.cgi?id=42031
5 > http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt
6
7 It looks like there is a discrepancy between the isec.pl link and the
8 original bugtraq post by Paul Starzetz. The bugtraq post says:
9
10 "Tested and known to be vulnerable kernel versions are all <= 2.2.25, <=
11 2.4.24 and <= 2.6.1. The 2.2.25 version of Linux kernel does not
12 ^^^^^
13 recognize the MREMAP_FIXED flag but this does not prevent the bug from
14 being successfully exploited. All users are encouraged to patch all
15 vulnerable systems as soon as appropriate vendor patches are released.
16 There is no hotfix for this vulnerablity. Limited per user virtual
17 memory still permits do_munmap() to fail."
18
19 Link:
20 http://securityfocus.com/archive/1/354284/2004-02-15/2004-02-21/0
21
22 The isec.pl link has the same paragraph except that it's noted as
23 <= 2.6.2 instead of 2.6.1. Anyone know what is going on here? I don't
24 mind updating my kernel and rebooting, but if I'd like to make sure I'm
25 doing it for a good reason :)
26
27 Alan
28 --
29 Alan <alan@×××××.org> - http://arcterex.net
30 --------------------------------------------------------------------
31 "There are only 3 real sports: bull-fighting, car racing and mountain
32 climbing. All the others are mere games." -- Hemingway
33
34 --
35 gentoo-dev@g.o mailing list

Replies