Linode.com Forum Forum Index Linode.com Forum
Linode Community Forums
 


New kernel exploit & Linode - DON'T TRY IT!

Click here to go to the original topic

 
       Linode.com Forum Forum Index -> General Discussion
Author Message
Xan



Joined: 08 Feb 2004
Posts: 311
Location: Austin

Posted: Sun Feb 10, 2008 4:38 pm    Post subject: New kernel exploit & Linode - DON'T TRY IT!  

You may have heard of the new kernel exploit that recently became public.

I just tried the exploit code on the Linode to see if it was vulnerable. It doesn't give me a root login, but it does hang the "machine", pretty hard, too. Took a few minutes for the Lish-initiated reboot to take effect; I thought I was going to have to fill a support ticket.

Best case scenario seems to be a graceless shutdown, so I would have to stamp it Not Recommended.
Back to top  
Xel



Joined: 15 Jun 2006
Posts: 5

Posted: Sun Feb 10, 2008 4:46 pm    Post subject:  

Yea... Listen to what he said... Because.... yea...

--Xel
Back to top  
caker



Joined: 15 Apr 2003
Posts: 2392
Location: Galloway, NJ

Posted: Sun Feb 10, 2008 5:03 pm    Post subject:  

As soon as the kernel devs settle on a fix, I'll be releasing new kernels...

-Chris
Back to top  
OverlordQ



Joined: 04 Jun 2004
Posts: 200

Posted: Mon Feb 11, 2008 12:04 am    Post subject:  

ONe of the 'exploits' patch it :)

Find it in the debian bug ticket
Back to top  
anderiv



Joined: 27 Apr 2004
Posts: 130

Posted: Mon Feb 11, 2008 1:44 am    Post subject:  

I believe GKH just committed the fix for this into 2.6.24.2:
Back to top  
caker



Joined: 15 Apr 2003
Posts: 2392
Location: Galloway, NJ

Posted: Mon Feb 11, 2008 11:47 am    Post subject:  

http://www.linode.com/forums/viewtopic.php?t=3104

-Chris
Back to top  
reallove



Joined: 27 Dec 2007
Posts: 8
Location: Cluj-Napoca , Romania

Posted: Mon Feb 11, 2008 12:47 pm    Post subject:  

(asking maybe a stupid question)
how can I upgrade to the latest 2.6.24.2 ,without recompiling myself the kernel ?
Back to top  
anderiv



Joined: 27 Apr 2004
Posts: 130

Posted: Mon Feb 11, 2008 12:48 pm    Post subject:  

You can select what kernel you're booting in your profile config in LPM (the members section of linode.com).

-erik
Back to top  
reallove



Joined: 27 Dec 2007
Posts: 8
Location: Cluj-Napoca , Romania

Posted: Mon Feb 11, 2008 12:51 pm    Post subject:  

thought so,but my latest 2.6 series is 2.6.18.8 (domU linode5).
Back to top  
anderiv



Joined: 27 Apr 2004
Posts: 130

Posted: Mon Feb 11, 2008 12:52 pm    Post subject:  

Ahh - you're on Xen. The kernel caker just released was a UML kernel. I haven't heard when the Xen kernel will be updated.
Back to top  
reallove



Joined: 27 Dec 2007
Posts: 8
Location: Cluj-Napoca , Romania

Posted: Mon Feb 11, 2008 12:53 pm    Post subject:  

considering the big impact of this exploit it would be great to have one also on xen :)
Back to top  
caker



Joined: 15 Apr 2003
Posts: 2392
Location: Galloway, NJ

Posted: Mon Feb 11, 2008 1:59 pm    Post subject:  

For you Xen people:

http://www.linode.com/forums/viewtopic.php?t=3105

-Chris
Back to top  
 
       Linode.com Forum Forum Index -> General Discussion
Page 1 of 1