Kernel Live Patch Security Notice LSN-0022-1

Discussion in 'News Aggregator' started by Packet Storm, 17 May 2017.

  1. Packet Storm

    Packet Storm Guest

    It was discovered that a use-after-free flaw existed in the filesystem encryption subsystem in the Linux kernel. A local attacker could use this to cause a denial of service (system crash). Andreas Gruenbacher and Jan Kara discovered that the filesystem implementation in the Linux kernel did not clear the setgid bit during a setxattr call. A local attacker could use this to possibly elevate group privileges.

    Continue reading...
     

Share This Page

Loading...