Tavis Ormandy and Julien Tinnes have discovered a severe security flaw in all 2.4 and 2.6 kernels since 2001 on all architectures. ‘Since it leads to the kernel executing code at NULL, the vulnerability is as trivial as it can get to exploit: an attacker can just put code in the first page that will get executed with kernel privileges.’ On their page you can find patches and exploit example scripts which proves the flaw, which you could use to see if you are affected by this problem.
Source: http://linux.slashdot.org




English