3 ms·
Oss-sec: Linux kernel futex local privilege escalation (CVE-2014-3153)
- musty 12y agoI love how this forum talks about "hack/ing" but when privesc bugs come around, nothing.
- scott_s 12y agoA follow-up comment describes how it works: http://seclists.org/oss-sec/2014/q2/469 http://seclists.org/oss-sec/2014/q2/469
- haberman 12y agoNice. I didn't quite understand though: > Specifically, the futex syscall can leave a queued kernel waiter hanging on the stack. By manipulating the stack with further syscalls, the waiter structure can be altered. Is the bug that the waiter is left on the stack, or that other syscalls can alter the stack? Allowing syscalls to alter the stack seems like a vulnerability regardless of what happens to be on the stack when it's altered.
- angersock 12y agoSee, this is what happens when (presumably white, male) programmers don't check their privilege.
- figglesonrails 12y agoThat made my day brighter. Sorry you're getting so many downvotes for that. :(
- voltagex_ 12y agoIsn't BPF a virtual machine inside the kernel? Does this have any impact on the likelihood of exploits?
- dalias 12y agoIs there any proper information on this issue? The patches do not apply cleanly against the latest stable kernel (3.14.5) and there's no indication I can find as to what version they're intended to be applied to.