• [^] # Re: Bugs et noyau

    Posté par . En réponse à la dépêche Nouvelle faille dans les noyaux 2.4 et 2.6. Évalué à 2.

    Un mail d'Alan Cox :
    De: Alan Cox
    On Fri, Jan 07, 2005 at 05:43:29PM -0500, Will Backman wrote:
    > Anyone tried the recently announced local root exploits against Fedora
    > Core? Do the stack protections and other stuff protect the Fedora
    > Kernel?

    Not in this case

    > I've manage a university shell server with many many student accounts.
    > Scared....

    Its fixed in 2.6.10-ac6 along with the following
    - DoS/oops in setsid (user triggerable) <==
    - Coda unverified user data (only if using Coda)
    - XFS unverified user data (only if using XFS)
    - Bridge ioctl (only if using bridge and already net_admin)
    - Rose ioctl (only if using rose and already net_admin)
    - SDLA firmware ioctls (only if net_admin and using sdla)


    Donc c'est déjà fixé dans la branche Alan Cox (mais ce n'est pas le même patch) depuis ac6 (le ac8 est sorti il y a 2 jours).
    On aurait pu passer 6 news en première page de plus et en une semaine seulement.
    Dans Fedora il n'y a pas BINFMT_AOUT de compilé donc il n'y a pas de risque. Je pense que beaucoup de distributions font de même.