<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Linux Kernel 2.6.22.16 and Prior Multiple Memory Corruption in Security</title>
<link>http://www.dslreports.com/forum/r20432885</link>
<description></description>
<language>en</language>
<pubDate>Fri, 09 Jan 2009 02:50:53 EDT</pubDate>
<lastBuildDate>Fri, 09 Jan 2009 02:50:53 EDT</lastBuildDate>

<item>
<title>Re: Linux Kernel 2.6.22.16 and Prior Multiple Memory Corruption</title>
<link>http://www.dslreports.com/forum/remark,20435649</link>
<description><![CDATA[<A HREF="/useremail/u/655964"><b>jdong</b></A> : <div class="bquote"><small>said by  oshooda <A HREF="/useremail/u/1294451"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Thanks for checking into that, and for the additional information.<br><br>I was pretty sure that this wasn't that much of an issue to begin with, but was a bit curious about why that kernel would still be in use if it were really as out of date as the first few posts might make it seem.<br> </div>Well it always does take time for fixes to trickle down the stream so to speak. Distributions, vendors , and local administrators all tend to make decisions on whether or not to include certain patches, and whether to do so *NOW* or group a bunch together every month instead of spamming the user every other day.<br><br>From an upstream perspective this bug is an old news but certainly there might be downstream distributions that still employ a vulnerable kernel.<br><small>--<br>Ubuntu MOTU Developer and Forums Council</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20435649</guid>
<pubDate>Mon, 05 May 2008 16:58:39 EDT</pubDate>
</item>

<item>
<title>Re: Linux Kernel 2.6.22.16 and Prior Multiple Memory Corruption</title>
<link>http://www.dslreports.com/forum/remark,20435618</link>
<description><![CDATA[<A HREF="/useremail/u/1294451"><b>oshooda</b></A> : Thanks for checking into that, and for the additional information.<br><br>I was pretty sure that this wasn't that much of an issue to begin with, but was a bit curious about why that kernel would still be in use if it were really as out of date as the first few posts might make it seem.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20435618</guid>
<pubDate>Mon, 05 May 2008 16:51:24 EDT</pubDate>
</item>

<item>
<title>Re: Linux Kernel 2.6.22.16 and Prior Multiple Memory Corruption</title>
<link>http://www.dslreports.com/forum/remark,20433783</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : Interesting, I'm glad others provided more complete and accurate information and pointed out that the vulnerability applies to a down level mod, and current versions are not vulnerable.   <br><br>I also heard there are several vulnerabilities in downlevel Windows XP ;) <br><br>All the more reason to stay as current as possible (allowing for testing of patches) regardless of platform.  <br><small>--<br>Mayors of New York come from nowhere and go nowhere.<br>Wallace Sayre (apparently, so do governors... )</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20433783</guid>
<pubDate>Mon, 05 May 2008 10:55:59 EDT</pubDate>
</item>

<item>
<title>Re: Linux Kernel 2.6.22.16 and Prior Multiple Memory Corruption</title>
<link>http://www.dslreports.com/forum/remark,20433372</link>
<description><![CDATA[<A HREF="/useremail/u/634007"><b>SUMware</b></A> : FWIW: openSUSE patch was built on 10 Feb. Thanks matunga.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20433372</guid>
<pubDate>Mon, 05 May 2008 08:55:57 EDT</pubDate>
</item>

<item>
<title>Re: Linux Kernel 2.6.22.16 and Prior Multiple Memory Corruption</title>
<link>http://www.dslreports.com/forum/remark,20433362</link>
<description><![CDATA[<A HREF="/useremail/u/655964"><b>jdong</b></A> : <div class="bquote"><small>said by  sivran <A HREF="/useremail/u/874811"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>But, it appears to be a local 'sploit. Meaning, as long as only I have  physical access to it, I'm not worried. Or did I miss something?<br><br>And my 2.4 deb box can continue chugging along, doing its duty quite efficiently.  :)<br> </div>Your Deb box actually had a DSA released to patch that up :)<br><br>And it's not even much of a root 'sploit locally -- it can only be triggered at all with certain modules actively loaded (the deprecated VIA southbridge OSS sound driver, some USB dongle gadget, one DRI module)<br><small>--<br>Ubuntu MOTU Developer and Forums Council</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20433362</guid>
<pubDate>Mon, 05 May 2008 08:52:58 EDT</pubDate>
</item>

<item>
<title>Re: Linux Kernel 2.6.22.16 and Prior Multiple Memory Corruption</title>
<link>http://www.dslreports.com/forum/remark,20433068</link>
<description><![CDATA[<A HREF="/useremail/u/352846"><b>antdude</b></A> : <div class="bquote"><small>said by  Trel <A HREF="/useremail/u/700992"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Thanks for the <strike>FUD</strike> info <strike>matunga</strike>.<br><br>According to: &raquo;<A HREF="http://kernel.org/" >kernel.org/</A>  The latest kernel is 2.6.55.1</div>2.6.55??!? :D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20433068</guid>
<pubDate>Mon, 05 May 2008 06:01:42 EDT</pubDate>
</item>

<item>
<title>Re: Linux Kernel 2.6.22.16 and Prior Multiple Memory Corruption</title>
<link>http://www.dslreports.com/forum/remark,20432885</link>
<description><![CDATA[<A HREF="/useremail/u/874811"><b>sivran</b></A> : But, it appears to be a local 'sploit. Meaning, as long as only I have  physical access to it, I'm not worried. Or did I miss something?<br><br>And my 2.4 deb box can continue chugging along, doing its duty quite efficiently.  :)<br><small>--<br>Think outside the fox...<A HREF="http://www.mozilla.org/projects/seamonkey/">Seamonkey</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20432885</guid>
<pubDate>Mon, 05 May 2008 02:51:43 EDT</pubDate>
</item>

<item>
<title>Re: Linux Kernel 2.6.22.16 and Prior Multiple Memory Corruption</title>
<link>http://www.dslreports.com/forum/remark,20432619</link>
<description><![CDATA[<A HREF="/useremail/u/655964"><b>jdong</b></A> : <div class="bquote"><small>said by  oshooda <A HREF="/useremail/u/1294451"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Hmmm... I couldn't help but wonder when Ubuntu Gutsy will catch up.<br><br><tt>me@cruncher:~$ uname -a<br>Linux cruncher 2.6.22-14-generic #1 SMP Tue Feb 12 07:42:25 UTC 2008 i686 GNU/Linux<br></tt><br> </div>I talked to one of our Security Team folks about this bug, and he says that he's aware of this and it's been scheduled for this week's security update to the kernel. They needed more time to test the fix for regressions than the other CVE's the last security release cycle.<br><br>(He also felt that the impact of this vulnerability is not particularly earth-shattering, as contrasted to, say, the vmsplice one)<br><small>--<br>Ubuntu MOTU Developer and Forums Council</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20432619</guid>
<pubDate>Mon, 05 May 2008 00:41:47 EDT</pubDate>
</item>

<item>
<title>Re: Linux Kernel 2.6.22.16 and Prior Multiple Memory Corruption</title>
<link>http://www.dslreports.com/forum/remark,20432435</link>
<description><![CDATA[<A HREF="/useremail/u/1294451"><b>oshooda</b></A> : Hmmm... I couldn't help but wonder when Ubuntu Gutsy will catch up.<br><br><tt>me@cruncher:~$ uname -a<br>Linux cruncher 2.6.22-14-generic #1 SMP Tue Feb 12 07:42:25 UTC 2008 i686 GNU/Linux<br></tt>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20432435</guid>
<pubDate>Sun, 04 May 2008 23:44:50 EDT</pubDate>
</item>

<item>
<title>Re: Linux Kernel 2.6.22.16 and Prior Multiple Memory Corruption</title>
<link>http://www.dslreports.com/forum/remark,20430310</link>
<description><![CDATA[<A HREF="/useremail/u/1432955"><b>Cabal</b></A> : My first thought was someone had resurrected a 3 month old thread, but I guess not. :D :uhh:]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20430310</guid>
<pubDate>Sun, 04 May 2008 14:36:08 EDT</pubDate>
</item>

<item>
<title>Re: Linux Kernel 2.6.22.16 and Prior Multiple Memory Corruption</title>
<link>http://www.dslreports.com/forum/remark,20430205</link>
<description><![CDATA[<A HREF="/useremail/u/655964"><b>jdong</b></A> : Most vendors have already fixed this vulnerability too; it was a pretty elusive one. And the scope of seriousness is not well represented here... it's extremely difficult to trigger these corruptions unless one had elevated access to begin with.<br><small>--<br>Ubuntu MOTU Developer and Forums Council</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20430205</guid>
<pubDate>Sun, 04 May 2008 13:59:50 EDT</pubDate>
</item>

<item>
<title>Re: Linux Kernel 2.6.22.16 and Prior Multiple Memory Corruption</title>
<link>http://www.dslreports.com/forum/remark,20429992</link>
<description><![CDATA[<A HREF="/useremail/u/700992"><b>Trel</b></A> : Thanks for the <strike>FUD</strike> info <strike>matunga</strike>.<br><br>According to: &raquo;<A HREF="http://kernel.org/" >kernel.org/</A>  The latest kernel is 2.6.55.1<br><br>Also, since you seem to like security focus, here's a nice link to their <b>solution</b> tab: &raquo;<A HREF="http://www.securityfocus.com/bid/27686/solution" >www.securityfocus.com/bid/27686/solution</A><br><br>Since you like quotes, here's one<br> <blockquote><small>quote:</small><hr>The vendor released Linux kernel 2.6.22.17 to address these issues. <hr></blockquote><br><br><small>--<br>/chown -R us:us /yourbase</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20429992</guid>
<pubDate>Sun, 04 May 2008 12:54:00 EDT</pubDate>
</item>

<item>
<title>Linux Kernel 2.6.22.16 and Prior Multiple Memory Corruption</title>
<link>http://www.dslreports.com/forum/remark,20429718</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : The Linux kernel is prone to multiple memory-corruption vulnerabilities due to insufficient range checking in certain fault handlers.<br><br>Local attackers could exploit these issues to cause denial-of-service conditions, <b>bypass certain security restrictions</b>, and potentially <b>access sensitive information or gain elevated privileges</b>.<br><br>These issues affect versions prior to 2.6.22.17. <br><br>&raquo;<A HREF="http://www.securityfocus.com/bid/27686/discuss" >www.securityfocus.com/bid/27686/discuss</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20429718</guid>
<pubDate>Sun, 04 May 2008 11:28:31 EDT</pubDate>
</item>

</channel>
</rss>
