Fixes for security hole in the Linux kernel [second update]
Summary
In August 2009 kernels 2.6.27.30 and 2.6.30.5 appeared, closing a hole that had existed since 2001 through which normal users could gain root privileges. Debian and Fedora delivered updates immediately and Ubuntu followed a day later, while Red Hat and SUSE initially only offered workarounds. Red Hat recommended disabling the affected network protocols, which rendered the public exploit ineffective.
Ideas
- Distributions react to the same kernel hole at different speeds.
- Disabling unused protocols can defuse an exploit until the patch arrives.
- Derived distributions such as CentOS depend on the original’s patch.
Insights
- The choice of distribution determines how long a system remains unprotected after a hole becomes known.
- Good workarounds are a contribution to security in their own right, not just a stopgap.
Facts
- The hole was fixed in 2.6.27.30 and 2.6.30.5.
- Ubuntu delivered fixes for 6.06 LTS, 8.04 LTS, 8.10 and 9.04.
References
Critique
- The report does not name the protocols that could be disabled, so readers cannot implement the workaround directly.
Recommendations
- Permanently block the loading of unused protocol modules via the modprobe configuration.
- With derived distributions, watch when the original delivers a patch.
Links to the original source and the Web Archive open in a new tab.