Clever attack exploits fully-patched Linux kernel

xoxoxoBruce • Jul 19, 2009 1:50 am
Seems like a serious problem.
Linux developers "tried to protect against it and what this exploit shows is that even with all the protections turned to super max, it's still possible for an attacker to figure out ways around this system," said Bas Alberts, senior security researcher at Immunity. "The interesting angle here is the actual thing that made it exploitable, the whole class of vulnerabilities, which is a very serious thing."

link
mbpark • Jul 19, 2009 10:03 am
Sounds like someone needs to turn on some compiler options.

I know the guy who found this exploit, and have personally met him at least once. He used to work for my friend Shawn at BurstNET years ago. He's a really smart guy who left BurstNET to work on GRSecurity.

It just goes to show that you really need to check everything when writing an OS.