Linux vmsplice Local Root Exploit

by Steve on May 17, 2010 · Filed Under Current Events, Linux vmsplice Local Root Exploit, Technology · 1 Comment 

linux-2.6: mmap() local root exploit

The Linux vmsplice local root exploit (CentOS, Redhat, Debian, Ubuntu) works with any Linux kernel version 2.6.17 to 2.6.24.1. If you don’t trust your users (which you shouldn’t), better compile a new kernel without vmsplice. This is the beauty of open source. The problem is now known so fixes are already on their way. As I write this, Red Hat is working on their update fix which will apply to RH and CentOS.