5 ms·
The blog post specifically thanks the Red Hat Security Team, but according to the Red Hat Bugzilla, no patch has been released yet for RHEL/CentOS: This issue
by tshtf 11y ago
The blog post specifically thanks the Red Hat Security Team, but according to the Red Hat Bugzilla, no patch has been released yet for RHEL/CentOS:
This issue affects the Linux kernels as shipped with Red Hat Enterprise Linux 7 and will be addressed in a future update.
https://bugzilla.redhat.com/show_bug.cgi?id=1297475 https://bugzilla.redhat.com/show_bug.cgi?id=1297475
Premature blog post?
- LinuxBender 11y agoTested on CentOS 7, fully patched. [ohadmin@localhost shm]$ ./cve_2016_0728 PP_KEY uid=99990, euid=99990 Increfing... This is taking a long time. I disabled SELinux and it has been cranking away for a while now. PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND 1140 ohadmin 20 0 8428 388 296 R 100.0 0.0 9:25.17 cve_2016_0728 No need to test on CentOS 6. Forgot how ancient that kernel is. Update: I am not having any luck getting this to work on CentOS 7. I even completely disabled SELinux (selinux=0 vs setenforce 0) Anyone else getting this to work?
- ryanlol 11y agoThat's not how you execute binaries, just "./cve_2016_0728 PP_KEY" is the correct syntax
- deleted 11y ago[deleted]
- LinuxBender 11y agoYes sorry. I will make the cheap excuse that I am recovering from food poisoning and don't quite have it all together. Thankfully I don't manage nuclear weapons, so we are all safe for now.
- 16 11y agoYou need to update the addresses of commit_creds() and prepare_kernel_cred() as per this: https://news.ycombinator.com/item?id=10931954 https://news.ycombinator.com/item?id=10931954
- LinuxBender 11y agoThe best I can get is an oops panic on CentOS 7. It appears smaps may be preventing the exploit from working.
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- rolandr 11y agoGiven that it looks like commits were just made 12 days ago (https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/security/keys?id=1d6d167c2efcfe9539d9cffb1a1be9c92e39c2c0 https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux....) or possibly as recently as 38 hours ago (https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/security/keys?id=5807fcaa9bf7dd87241df739161c119cf78a6bc4 https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux....), perhaps only 4.4 has the fix?