republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Linux Kernel 2.6.22.16 and Prior Multiple Memory Corruption
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Identity theft solutions: fraud alerts, credit monitoring.. »
« AVG pro 7.5 annoying pop-up till Decenber?  
AuthorAll Replies

oshooda

join:2005-11-26
reply to kluess_
Re: Linux Kernel 2.6.22.16 and Prior Multiple Memory Corruption

Hmmm... I couldn't help but wonder when Ubuntu Gutsy will catch up.

me@cruncher:~$ uname -a
Linux cruncher 2.6.22-14-generic #1 SMP Tue Feb 12 07:42:25 UTC 2008 i686 GNU/Linux


jdong
Eat A Beaver, Save A Tree.
Premium
join:2002-07-09
Rochester, MI
clubs:

said by oshooda See Profile :

Hmmm... I couldn't help but wonder when Ubuntu Gutsy will catch up.

me@cruncher:~$ uname -a
Linux cruncher 2.6.22-14-generic #1 SMP Tue Feb 12 07:42:25 UTC 2008 i686 GNU/Linux

I talked to one of our Security Team folks about this bug, and he says that he's aware of this and it's been scheduled for this week's security update to the kernel. They needed more time to test the fix for regressions than the other CVE's the last security release cycle.

(He also felt that the impact of this vulnerability is not particularly earth-shattering, as contrasted to, say, the vmsplice one)
--
Ubuntu MOTU Developer and Forums Council


sivran
God Save The Suite
Premium
join:2003-09-15
Arlington, TX
clubs:
·RoadRunner Cable
·Comcast

But, it appears to be a local 'sploit. Meaning, as long as only I have physical access to it, I'm not worried. Or did I miss something?

And my 2.4 deb box can continue chugging along, doing its duty quite efficiently.
--
Think outside the fox...Seamonkey


jdong
Eat A Beaver, Save A Tree.
Premium
join:2002-07-09
Rochester, MI
clubs:

said by sivran See Profile :

But, it appears to be a local 'sploit. Meaning, as long as only I have physical access to it, I'm not worried. Or did I miss something?

And my 2.4 deb box can continue chugging along, doing its duty quite efficiently.
Your Deb box actually had a DSA released to patch that up

And it's not even much of a root 'sploit locally -- it can only be triggered at all with certain modules actively loaded (the deprecated VIA southbridge OSS sound driver, some USB dongle gadget, one DRI module)
--
Ubuntu MOTU Developer and Forums Council

oshooda

join:2005-11-26

reply to jdong
Thanks for checking into that, and for the additional information.

I was pretty sure that this wasn't that much of an issue to begin with, but was a bit curious about why that kernel would still be in use if it were really as out of date as the first few posts might make it seem.


jdong
Eat A Beaver, Save A Tree.
Premium
join:2002-07-09
Rochester, MI
clubs:

said by oshooda See Profile :

Thanks for checking into that, and for the additional information.

I was pretty sure that this wasn't that much of an issue to begin with, but was a bit curious about why that kernel would still be in use if it were really as out of date as the first few posts might make it seem.
Well it always does take time for fixes to trickle down the stream so to speak. Distributions, vendors , and local administrators all tend to make decisions on whether or not to include certain patches, and whether to do so *NOW* or group a bunch together every month instead of spamming the user every other day.

From an upstream perspective this bug is an old news but certainly there might be downstream distributions that still employ a vulnerable kernel.
--
Ubuntu MOTU Developer and Forums Council
Forums » Up and Running » Security » SecurityIdentity theft solutions: fraud alerts, credit monitoring.. »
« AVG pro 7.5 annoying pop-up till Decenber?  


Saturday, 11-Oct 13:55:23 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [140] It's Cable TV Rate Hike Season
· [97] Wholesale Bandwidth Prices Still Dropping
· [95] Is Comcast Cooking Up a 22Mbps/5Mbps Tier?
· [95] Symmetrical FiOS No Longer Qualifies For Bundle Discounts
· [84] Time Warner's Ugly Feud With LIN TV
· [77] Half Of New iPhone Owners Came From Verizon
· [70] Supreme Court TiVo/Echostar Ruling
· [70] Microsoft: U.S. Broadband Policy 'Total Failure'
· [67] Verizon Unveils Blackberry Storm
· [64] XOHM Online In Additional Launch Markets
Most people now reading
· Should hourly workers work for free thru lunch [General Questions]
· Homeowner Says Cable Mistake Filled Kitchen With Raw Sewage [Comcast Cable TV]
· [News] GM and Chrysler talking about merger. [Automotive]
· Where did the money go? [General Questions]
· [Connectivity] Neighbor using MY router to connect to Internet? [Comcast HSI]
· 516v6 upgrade [TekSavvy]
· [video] Will he make it? [56k lookout! (broadband heavy)]
· Going to Disneyworld, Need ideas [General Questions]
· Safty Question about K & T wiring. Very worried... [Home Repair & Improvement]