Root exploit for Linux kernel in circulation
Two exploits have been published for a security vulnerability in the Linux kernel. They allow restricted users to escalate their privileges to that of the superuser. Systems on which multiple users work in parallel are particularly at risk of an attacker exploiting the vulnerability to manipulate or gain control of a system. In tests by the heise Security editorial team, one of the exploits opened a shell with root privileges on an Ubuntu system.
The vulnerability arises from a bug in the way in which user programs deal with pointers relating to the
vmsplice function, introduced in kernel version 2.6.17. Failure to check pointers when calling the
vmsplice_to_user function allows read and write access to arbitrary memory areas. The kernel developers have not released a detailed description of the bug - the changelog for the first attempt at a fix in kernel 126.96.36.199 merely states "splice: missing user pointer access verification (CVE-2008-0009/10)". The CVE entry is currently empty. Shortly after the kernel update it was still possible to exploit the vulnerability despite the patch, for which reason the developers took a second stab at it with version 188.8.131.52.
This solution also seems to be still subject to some uncertainty, as the comments accompanying the patch indicate that there is still some testing to be done to ensure that it really works as it should. There are also unconfirmed scattered reports that the patch in version 184.108.40.206 reopens the original vulnerability. Operators of multi-user systems should nevertheless switch to the latest version of the kernel or install packages from their Linux distributor as soon as they are made available.
- ChangeLog 220.127.116.11, changes in Kernel 18.104.22.168
- ChangeLog 22.214.171.124, changes in Kernel 126.96.36.199
- Linux vmsplice Local Root Exploit (2.6.17 - 188.8.131.52), exploit on Milw0rm
- Linux vmsplice Local Root Exploit (2.6.23 - 2.6.24), exploit on Milw0rm