bk99.de entertain the web since 1997

Fixes for security hole in the Linux kernel [second update]

Summary

In August 2009 kernels 2.6.27.30 and 2.6.30.5 appeared, closing a hole that had existed since 2001 through which normal users could gain root privileges. Debian and Fedora delivered updates immediately and Ubuntu followed a day later, while Red Hat and SUSE initially only offered workarounds. Red Hat recommended disabling the affected network protocols, which rendered the public exploit ineffective.

Ideas

  • Distributions react to the same kernel hole at different speeds.
  • Disabling unused protocols can defuse an exploit until the patch arrives.
  • Derived distributions such as CentOS depend on the original’s patch.

Insights

  • The choice of distribution determines how long a system remains unprotected after a hole becomes known.
  • Good workarounds are a contribution to security in their own right, not just a stopgap.

Facts

  • The hole was fixed in 2.6.27.30 and 2.6.30.5.
  • Ubuntu delivered fixes for 6.06 LTS, 8.04 LTS, 8.10 and 9.04.

References

Critique

  • The report does not name the protocols that could be disabled, so readers cannot implement the workaround directly.

Recommendations

  • Permanently block the loading of unused protocol modules via the modprobe configuration.
  • With derived distributions, watch when the original delivers a patch.

Read the original article

Search the Web Archive