Linux Today: Linux News On Internet Time.

Patching CVE-2008-0600, Local Root Exploit

Feb 12, 2008, 13:45 (1 Talkback[s])

"Patches for a much publicized Linux kernel local root exploit were released today as,, and The latest bug, labeled as CVE-2008-0600, was introduced by the vmsplice() system call and added into the 2.6 kernel in 2.6.17. It is the third in a series of root exploits surrounding the same system call, the two earlier bugs being CVE-2008-0009 and CVE-2008-0010. Easily obtained exploits exist for both the older CVE-2008-0010 which affected the 2.6.23 and 2.6.24 kernels, and the latest CVE-2008-0600, allowing a local non-root user to gain root permissions..."

Complete Story

Related Stories: