Security updates: root kernel hole threatens IBM’s AIX operating system
Summary
In 2021 IBM closed three holes in the AIX kernel, including CVE-2021-29801, through which a local user without privileges could gain root access. Two further medium-risk holes allowed the kernel to be crashed. IBM listed the fixed AIX and VIOS versions in an advisory.
Ideas
- Proprietary Unix systems also have local kernel holes with root consequences.
- Besides privilege escalation, kernel bugs can bring down the whole system.
- The VIOS virtualisation layer was affected as well.
Insights
- Local holes must be taken seriously on multi-user and application servers.
- Few public details make your own risk assessment harder.
Facts
- The root hole CVE-2021-29801 was rated “high”.
- The DoS holes CVE-2021-29727 and CVE-2021-29862 were rated “medium”.
References
Critique
- The report reproduces little more than the vendor’s brief description.
Recommendations
- Apply security updates regularly on less frequently maintained Unix systems as well.
- Restrict local logins on production servers to what is necessary.
Links to the original source and the Web Archive open in a new tab.