[rsbac] 2.6.11.2 - epoll vulnerability

murf murf at post.cz
Wed Mar 9 20:55:39 CET 2005


Hello,

probably you have noticed that there is a new patch released today 
for 2.6 kerns.

It repairs vulnerability in epoll. This vulnerability 
can potentially facilitate privilege escalation. 
Sploit has been walking around for some time.

Patch can be downloaded here:
http://kernel.org/pub/linux/kernel/v2.6/patch-2.6.11.2.gz

I applied it to the prepatched kernel 2.6.11-rsbac-1.2.4-bf2
along with patch-2.6.11.1.gz. After compiling and installing new
kernel it seems to work good.

Keep in mind that 2.6 branch is still for testing and 
not for real using on product servers.

Rgds,

Murf


More information about the rsbac mailing list