New Linux kernels close security holes
Summary
In August 2006 new Linux kernels of the 2.4.33, 2.6.16 and 2.6.17 series appeared that closed security holes. A bug in the SCTP function sctp_make_abort_user allowed logged-in attackers to execute code with higher privileges. A UDF bug crashed the system and had not yet been fixed in 2.4.33.
Ideas
- Rarely used protocols such as SCTP still bring attack surface into the kernel.
- File system code can also crash the entire system.
- Fixes for older kernel series sometimes arrive later than for newer ones.
Insights
- Every loaded kernel module extends the attack surface, even if nobody uses it deliberately.
- Older kernel series receive security fixes with a delay.
Facts
- The UDF bug affected all three series and was initially not fixed in 2.4.33.
References
Critique
- The report does not say whether the SCTP module is loaded automatically, and thus how many systems were really affected.
Recommendations
- Disable or block kernel modules for protocols you do not use, such as SCTP.
- Apply kernel updates promptly on systems with local users.
Links to the original source and the Web Archive open in a new tab.