[arch-general] Kernel Rootexploit

Moritz Rudert helios at h-ix.net
Fri Sep 17 11:39:12 EDT 2010


 Hi everybody,
unfortunately today a new root exploit appeared.

Look at: http://sota.gen.nz/compat2/

After some tests I can say: It works on Archlinux and Ubuntu, but not on
debian.

The "bugfix" found on http://seclists.org/fulldisclosure/2010/Sep/273
does not work on Arch and Ubuntu.

The only current fix is to patch the kernel.
allspark and me built new versions of the current Arch-kernel and the
LTS-kernel.

Kernel and PKGBUILD-tar can be found on:
http://lorelei.h-ix.net/downloads/kernel26-2.6.35.4-1-x86_64.pkg.tar.gz
http://lorelei.h-ix.net/downloads/kernel26-2.6.35.4-1.src.tar.gz
http://lorelei.h-ix.net/downloads/kernel26-lts-2.6.32.21-2.src.tar.gz
http://lorelei.h-ix.net/downloads/kernel26-lts-2.6.32.21-2-x86_64.pkg.tar.gz

I will upload a new version of kernel26-vanilla to AUR later this day.

Greetings
Moritz <helios> Rudert


More information about the arch-general mailing list