ptrace vulnerability in 2.2.x kernel and 7.0
Chris Whip <[email protected]> Wed, 19 Mar 2003 09:35:48 -0800
| Newsgroups | gmane.linux.redhat.release.guinness |
|---|---|
| Message-ID | <[email protected]> |
It's been two days since the release of the 2.4 kernel ptrace vulnerability bugfix rpm. Alan Cox's mail concerning the hole states that 2.2 kernels are also vulnerable, so Red Hat 7.0 systems should be vulnerable. No RPM yet The errata EOL for 7.0 is not here yet, IIRC, so a patch should be forthcoming. It would be nice to have this confirmed, though, and be advised of any potential workarounds. On Slashdot, Pat Volkerding from Slackware suggested echo "/nonexistent/file" > /proc/sys/kernel/modprobe to turn off kmod in the interim. It seems to work OK, although I get warnings about net-pf-10, which I believe is ipv6 and not needed in my setup. Cheers, -- Chris -- -- Chris Whip - Systems administrator, Drizzle Internet NW - [email protected]