WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-devel

[Xen-devel] Xen immune to latest Linux exploit

To: xen-devel@xxxxxxxxxxxxxxxxxxxxx
Subject: [Xen-devel] Xen immune to latest Linux exploit
From: Keir Fraser <Keir.Fraser@xxxxxxxxxxxx>
Date: Sat, 12 Jun 2004 09:52:09 +0100
Delivery-date: Sat, 12 Jun 2004 09:54:05 +0100
Envelope-to: steven.hand@xxxxxxxxxxxx
List-archive: <http://sourceforge.net/mailarchive/forum.php?forum=xen-devel>
List-help: <mailto:xen-devel-request@lists.sourceforge.net?subject=help>
List-id: List for Xen developers <xen-devel.lists.sourceforge.net>
List-post: <mailto:xen-devel@lists.sourceforge.net>
List-subscribe: <https://lists.sourceforge.net/lists/listinfo/xen-devel>, <mailto:xen-devel-request@lists.sourceforge.net?subject=subscribe>
List-unsubscribe: <https://lists.sourceforge.net/lists/listinfo/xen-devel>, <mailto:xen-devel-request@lists.sourceforge.net?subject=unsubscribe>
Sender: xen-devel-admin@xxxxxxxxxxxxxxxxxxxxx
If you're running multi-user Linux systems then you may be interested
to know about the latest-published user exploit:
 <http://linuxreviews.org/news/2004-06-11_kernel_crash/index.html>

It affects up to and including the latest vanilla 2.4 and 2.6 trees
(2.4.26,2.6.6). Compiling and running the linked source fragment will
cause such systems to lock up -- AFAICS interrupts and softirqs carry
on working (e.g., I can ping the system) but all process activity is
gone. 

Further bad news is that the kernel developers don't seem to have
responded to this at all as yet. Not even any discussion on the
linux-kernel list.

Better news is that certain gentoo-patched kernels are reported not to
have this flaw. Even better is that if you are running XenoLinux you
are similarly immune. :-)

 -- Keir


-------------------------------------------------------
This SF.Net email is sponsored by the new InstallShield X.
>From Windows to Linux, servers to mobile, InstallShield X is the
one installation-authoring solution that does it all. Learn more and
evaluate today! http://www.installshield.com/Dev2Dev/0504
_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxxxx
https://lists.sourceforge.net/lists/listinfo/xen-devel

<Prev in Thread] Current Thread [Next in Thread>
  • [Xen-devel] Xen immune to latest Linux exploit, Keir Fraser <=