TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Multiple Bugs in OpenBSD Kernel

199 pointsby hasselalmost 9 years ago

11 comments

djcapelisalmost 9 years ago
It sounds like one local privilege escalation (possibly?) and a series of crashers?<p>Honestly walking away with those being the highest severity bugs is a credit to the OpenBSD team and their focus on security. They&#x27;re totally bugs and it sounds like they&#x27;re getting fixed immediately, but... many kernels fix these types of things all the time and don&#x27;t even consider them security bugs.
评论 #12098404 未加载
评论 #12100671 未加载
评论 #12098364 未加载
评论 #12098365 未加载
SEJeffalmost 9 years ago
And for those not aware, Project Triforce, is NCC&#x27;s effort to run the wonderful fuzzer American Fuzzy Lop, on everything:<p><a href="https:&#x2F;&#x2F;www.nccgroup.trust&#x2F;us&#x2F;about-us&#x2F;newsroom-and-events&#x2F;blog&#x2F;2016&#x2F;june&#x2F;project-triforce-run-afl-on-everything&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.nccgroup.trust&#x2F;us&#x2F;about-us&#x2F;newsroom-and-events&#x2F;b...</a>
评论 #12098000 未加载
epmatswalmost 9 years ago
I wish someone would release something like Fuzzing At Home. I&#x27;ve got computer power to throw at it, but I don&#x27;t really have the expertise to do the setup work...
评论 #12098312 未加载
评论 #12100192 未加载
lbradstreetalmost 9 years ago
It&#x27;s striking how many of these issues cause panics because of assertions that were already in the code. Without good assertion use, I would assume that many of these would have been much worse.
jwilkalmost 9 years ago
More readable archived copy: <a href="http:&#x2F;&#x2F;permalink.gmane.org&#x2F;gmane.comp.security.oss.general&#x2F;19946" rel="nofollow">http:&#x2F;&#x2F;permalink.gmane.org&#x2F;gmane.comp.security.oss.general&#x2F;1...</a><p>(I&#x27;m not a fan of gmane, but it did a better job with this particular mail than the alternatives.)
评论 #12097948 未加载
djgsalmost 9 years ago
Ted U. announced that usermount will be removed in OpenBSD 6.0<p><a href="https:&#x2F;&#x2F;marc.info&#x2F;?l=openbsd-announce&amp;m=146854517406640&amp;w=2" rel="nofollow">https:&#x2F;&#x2F;marc.info&#x2F;?l=openbsd-announce&amp;m=146854517406640&amp;w=2</a>
评论 #12102059 未加载
gbrown_almost 9 years ago
Firstly glad to see these reported and fixed.<p>Secondly how many of these were remotely exploitable? Yes OpenBSD is limited in it&#x27;s exposure with the &quot;base system&quot;, but it seems like few of these pose as &quot;holes&quot; for the system? Arguably pledge(2) could factor into this, maybe? I&#x27;ll let someone better qualified comment.<p>Again glad to see these fixed. But is the baseline free user access to the whole system for NetSec&#x2F; OpSec these days? I don&#x27;t know maybe it is.<p>I&#x27;m just reluctant to have to read through the HN, &quot;OMG OpenBSD had CVEs&quot; and &quot;C is insecure&quot;. Arguably the later has some merit but C isn&#x27;t going away anytime soon, for better or for worse.
评论 #12098158 未加载
评论 #12098416 未加载
smhendersonalmost 9 years ago
While a bit surprising to see so many at once in OBSD kudos to the team for the rapid response and to those who found the bugs for their responsible disclosure.
lifeisstillgoodalmost 9 years ago
Fuzzing is not something I have looked at seriously (to be honest it seems like asking clients to take up running before walking) but the outcomes are ... Impressive.
评论 #12097837 未加载
评论 #12097838 未加载
评论 #12097839 未加载
hiphopyoalmost 9 years ago
Compared to other OSes and distros this is one in a million.
rhabarbaalmost 9 years ago
Multiple (!) security issues in OpenBSD (!).<p>OK.<p>We&#x27;re doomed.
评论 #12097892 未加载