Re: uselib() & 2.6.X?

From: Marcelo Tosatti (marcelo.tosatti_at_cyclades.com)
Date: 01/07/05

  • Next message: Marcelo Tosatti: "Re: Fix for new elf_loader bug?"
    Date:	Fri, 7 Jan 2005 15:07:12 -0200
    To: Lukasz Trabinski <lukasz@wsisiz.edu.pl>
    
    
    

    On Fri, Jan 07, 2005 at 04:59:22PM +0100, Lukasz Trabinski wrote:
    > Hello
    >
    >
    > http://isec.pl/vulnerabilities/isec-0021-uselib.txt
    >
    > [...]
    > Locally exploitable flaws have been found in the Linux binary format
    > loaders' uselib() functions that allow local users to gain root
    > privileges.
    > [...]
    > Version: 2.4 up to and including 2.4.29-rc2, 2.6 up to and including 2.6.10
    > [...]
    >
    > It's was fixed by Marcelo on 2.4.29-rc1. Thank's :)
    > What about 2.6.X? Is any patch available? I don't see any changes
    > around binfmt_elf in 2.6.10-bk10?

    2.6.10-ac contains a version of the fix.

    Attached is what going to be merged in mainline, most likely.

    
    

    -
    To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
    the body of a message to majordomo@vger.kernel.org
    More majordomo info at http://vger.kernel.org/majordomo-info.html
    Please read the FAQ at http://www.tux.org/lkml/



  • Next message: Marcelo Tosatti: "Re: Fix for new elf_loader bug?"

    Relevant Pages

    • uselib() & 2.6.X?
      ... loaders' uselibfunctions that allow local users to gain root ... privileges. ... To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/ ...
      (Linux-Kernel)
    • Re: /proc/sys/kernel/pid_max issues
      ... > Prior to the call being handled, ... Some random innocent process, ... code that is about to spread some of its privileges ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: [patch] Real-Time Preemption, -RT-2.6.10-rc2-mm2-V0.7.30-2
      ... - boot / telinit 5 OK ... - su'd to get privileges ... - started scripts to record data ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: [PATCH] [request for inclusion] Realtime LSM
      ... users to tie up resources. ... > a nice way to handle privileges for these guys. ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: 2.6.11-rc3-mm2
      ... >>issue that has a much wider potential audience than pro audio users, ... > the system after giving out RT privileges. ... specified users when running specified programs would have wider ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)