Language Selection

English French German Italian Portuguese Spanish

Two Vulnerabilities Provide Root Access on Linux

Filed under
Linux
Security

Two new vulnerabilities affecting Linux were uncovered this week that could potentially be used by malicious hackers to gain root privileges.

One vulnerability, which was reported on Tuesday by security firm VSR, arises from a flaw in the implementation of the Reliable Datagram Sockets protocol (RDS) in versions 2.6.30 through 2.6.36-rc8 of the Linux kernel.

Known as CVE-2010-3904, the bug could allow a local attacker to issue specially crafted socket function calls to write arbitrary values into kernel memory and thereby escalate privileges to root, giving the attacker "superuser," administrator status.

rest here




Linux Kernel Update

pcworld.com: A new update to the Linux kernel adds a raft of security features, driver support, and other enhancements without increasing the overall size of the kernel at all.

That's a rarity, given that enhancements in each update have tended over the years to increase the kernel's size. This time around, though, there are a number of improvements that will be visible to users, but without any extra mass.

It won't be long before this new kernel is integrated into most popular Linux distributions. Here are some of the highlights of what users can expect.

Beefed Up Security

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

More in Tux Machines

Red Hat News

Leftovers: Ubuntu

Linux Devices

  • AsteroidOS 1.0 Alpha on the Asus Zenwatch 3
    In a previous article, I published a small userspace image and Linux kernel for the Zenwatch 3 that enables root access with SSH over USB on the watch. By now, I reached my initial goal to get AsteroidOS, the alternative Android Wear operating system, running on the Zenwatch 3. Similar to SailfishOS and Ubuntu Touch, AsteroidOS uses the original Android kernel - a patched Linux kernel - with a GNU/Linux userspace that, in turn, also uses some of the original, closed-source Android libraries to access certain hardware like the GPU. As the Android libraries expect a different software ecosystem, e.g., a different C library called bionic, we cannot simply call the Android libraries from within a common GNU/Linux application. Instead, we need an additional software layer that translates between the Android and the common GNU/Linux world. This layer is called libhybris.
  • How Ironic: Harman Kardon’s Microsoft Cortana Speaker Is Powered by Linux
    Harman Kardon, the company recently acquired by Samsung, has developed its very own Cortana speaker, which is very similar to the Amazon Echo but featuring Microsoft’s famous digital assistant. And since Cortana is the key feature of this little device, it only makes sense for Harman Kardon to turn to Windows 10 to power the device. And yet, it looks like the so-called Harman Kardon is actually running Linux.
  • MontaVista® Launches Carrier Grade eXpress®(CGX) 2.2 Linux® for 5G and IoT at MWC 2017
  • The Numbers Article for Mobile in 2017 - All the Statistics You Could Ask For
    Mobile is the hottest industry. Banking and payments are rushing to mobile. Governments doing healthcare and education with mobile. Travel from airlines to taxis to trains and busses to hotel bookings is going mobile. Your driver's licence is migrating to the mobile phone as are your keys to your home. And all the other big tech stories from Internet of Things (IoT) to 'Big Data' analytics to Cloud computing - are all dependent on mobile. And next week we have the massive industry event in Barcelona, Mobile World Congress. My brand new TomiAhonen Almanac 2017 is now finished and is released today. So this is the perfect time to do my annual 'State of Mobile' blog of the major statistics. What are the big numbers. Lets start with reach. Yes, mobile is by far the most widely-spread communication technology humankind has ever witnessed.
  • Tizen Store Expands Its Service Coverage to 222 Countries
    The Tizen Store, as the name suggests, is the Tizen Application Store for developers to publish their free and paid for Tizen apps. In April 2015, we saw the store expand it’s coverage to include 182 countries, which was mainly for FREE apps, but we saw this as setting the foundation for providing paid for apps further down the road.

Android Leftovers