TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Hole in Linux kernel provides root rights

69 点作者 spahl超过 14 年前

6 条评论

jacquesm超过 14 年前
Strike one for regression testing.<p>I tried the exploit on all our 64 bit boxes and it seems to fail on every one of them.<p>Here are the uname -a strings from a representative sample:<p>Linux c01_04.ttc.com 2.6.17.11 #3 SMP Wed Oct 10 06:16:52 EDT 2007 x86_64 GNU/Linux<p>Linux root-desktop 2.6.31-16-generic #53-Ubuntu SMP Tue Dec 8 04:02:15 UTC 2009 x86_64 GNU/Linux<p>Linux eleven.ttc.com 2.6.15 #2 SMP Thu Mar 9 09:06:54 EST 2006 x86_64 GNU/Linux<p>Linux backup01.ttc.com 2.6.25-14.fc9.x86_64 #1 SMP Thu May 1 06:06:21 EDT 2008 x86_64 x86_64 x86_64 GNU/Linux<p>On the last one it exits with 'symbol table not available, aborting!'.<p>Off-topic, how many of you actually review a program like this before running it?
评论 #1707294 未加载
评论 #1707487 未加载
评论 #1707325 未加载
评论 #1707296 未加载
jsean超过 14 年前
How come Robert sucks?<p>edit: ok, if you didn't notice source's filename; <a href="http://sota.gen.nz/compat2/robert_you_suck.c" rel="nofollow">http://sota.gen.nz/compat2/robert_you_suck.c</a><p>And just in case... also ;)
评论 #1707312 未加载
评论 #1707246 未加载
评论 #1707322 未加载
rbanffy超过 14 年前
Anyone would like to explain why stuff like this is not automatically tested? Introducing tests into the kernel source tree would actually help its development and prevent incidents like this, wouldn't it?
评论 #1708035 未加载
评论 #1708315 未加载
jrockway超过 14 年前
Incidentally, there are several buffer overflow errors in the exploit code.
评论 #1709490 未加载
bustamove超过 14 年前
just tried the exploit on my slicehost box and it successfully root it!
bustamove超过 14 年前
~# uname -a Linux slice<i></i><i></i> 2.6.32.12-rscloud #26 SMP Mon May 17 12:35:34 UTC 2010 x86_64 GNU/Linux