store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Sun May 19, 2013 3:44 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 8 posts ] 
Author Message
 Post subject: Local vulnerability in all Linux kernels
Unread postPosted: Fri Aug 14, 2009 5:58 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3242
Location: Chantilly, VA
There is a local vulnerability in all Linux kernels. ASL includes countermeasures to protect you from this vulnerability. However, because thats never good enough for us we're putting out an update that closes the Null Dereferencing flaw once and for all. This is not a critical update, so we recommend you test the update on non-production machines before putting into production.

Also, this vulnerability can only effects systems if the following protocols are enabled (which is not the case by default in ASL either) - and its only a local exploit:

PF_APPLETALK
PF_IPX
PF_IRDA
PF_X25
PF_AX25
PF_BLUETOOTH
PF_IUCV
IPPROTO_SCTP/PF_INET6
PF_PPPOX
PF_ISDN

The latest ASL kernel is: 2.6.29.6-1.art

If you are not running an ASL kernel, then you are highly recommended to check with your vendor to make sure they close this hole as those kernels do not have any protections against this vulnerability. You can on non-ASL kernels disable these protocols, but theres no guarantee that the issue will be mitigated. Upgrading your kernel is the recommended option.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Local vulnerability in all Linux kernels
Unread postPosted: Sat Aug 15, 2009 7:26 am 
Offline
Forum Regular
Forum Regular

Joined: Tue Jan 15, 2008 3:57 am
Posts: 478
Location: Netherlands
Is this in the Yum channel? because I just wanted to update but via YUM I did not get a new kernel?

_________________
best regards,

http://hosting.ber-art.nl
Professional Secure Linux Plesk Hosting


Top
 Profile  
 
 Post subject: Re: Local vulnerability in all Linux kernels
Unread postPosted: Sat Aug 15, 2009 7:52 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
Kernel 2.6.29.6-1.art is still in the asl-2.0-testing channel.

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject: Re: Local vulnerability in all Linux kernels
Unread postPosted: Sun Aug 16, 2009 5:12 am 
Offline
Forum Regular
Forum Regular

Joined: Tue Jan 15, 2008 3:57 am
Posts: 478
Location: Netherlands
Ah, ok thx breun, that explains it :)

_________________
best regards,

http://hosting.ber-art.nl
Professional Secure Linux Plesk Hosting


Top
 Profile  
 
 Post subject: Re: Local vulnerability in all Linux kernels
Unread postPosted: Sun Aug 16, 2009 7:10 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
It was released to stable yesterday, but now there is another reason people might not see the update: the new 32-bit ASL kernel is i586, while previous versions were i686 and this causes yum to not pick up the update.

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject: Re: Local vulnerability in all Linux kernels
Unread postPosted: Sun Aug 16, 2009 10:45 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
Apparently ASL adopted the new Red Hat standard for kernel packages. The new i686 kernels are all PAE kernels and the non-PAE kernels are i586. Eventually the non-PAE kernels will be discontinued, so you'll probably want to install the kernel-PAE package if you're on i686:

Code:
yum install kernel-PAE


This kernel will also let you use more than 4 GB RAM on a 32-bit OS, although it is better to run a 64-bit OS if you plan on doing that.

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject: Re: Local vulnerability in all Linux kernels
Unread postPosted: Mon Aug 17, 2009 11:26 am 
Offline
Forum Regular
Forum Regular

Joined: Tue Jan 15, 2008 3:57 am
Posts: 478
Location: Netherlands
If I installed the .586 first can I just install the PEA kernel after? Or do I wait for the next update? (edit:// just tried, this worked)

Thx breun now I know why YUM did not pickup on this :)

Still some issues after the update: viewtopic.php?f=3&t=3371

_________________
best regards,

http://hosting.ber-art.nl
Professional Secure Linux Plesk Hosting


Top
 Profile  
 
 Post subject: Re: Local vulnerability in all Linux kernels
Unread postPosted: Mon Aug 17, 2009 1:09 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7418
Location: earth
Those issues are false positives, they can be safely ignored.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 8 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group