Gentoo Archives: gentoo-hardened

From: Natanael Copa <natanael.copa@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] latest kernel exploit patch for vmsplice coming?
Date: Mon, 11 Feb 2008 09:35:52
Message-Id: 1202722546.24169.17.camel@nc.nor.wtbts.org
In Reply to: Re: [gentoo-hardened] latest kernel exploit patch for vmsplice coming? by pageexec@freemail.hu
1 On Sun, 2008-02-10 at 23:41 +0200, pageexec@××××××××.hu wrote:
2 > On 10 Feb 2008 at 22:32, Alex Howells wrote:
3 >
4 > > I wasn't sure we needed a special patch?
5 >
6 > it's a kernel bug so it obviously needs a patch, a fix is in the linus
7 > tree now, i guess it'll be backported quickly.
8 >
9 > > Every single box I've tried this exploit on ranging from
10 > > hardened-sources-2.6.17 through to hardened-sources-2.6.23, its been
11 > > nailed. Could just be my kernel configuration?
12 >
13 > UDEREF prevents exploitation for good, even KERNEXEC alone would
14 > prevent the kind of code execution that this exploit relies on.
15
16 I tried the patch on various systems. The grsecurity patches does
17 protect this kind of issues.
18
19 This is is a real life example of why grsecurity is good for you.
20
21 Thanks!
22
23 -nc
24
25 --
26 gentoo-hardened@l.g.o mailing list