Language Selection

English French German Italian Portuguese Spanish

Linux Kernel Local DoS and Security Bypass Issues

Filed under
Security

Rated as : Low Risk

Multiple vulnerabilities were identified in Linux Kernel, which could be exploited by local attackers to cause a denial of service or bypass certain security restrictions.

The first issue is due to a memory leak error in "/security/keys/request_key_auth.c", which could be exploited by malicious users to cause a denial of service.

The second vulnerability is due to a memory leak error in "/fs/namei.c" when the CONFIG_AUDITSYSCALL option is enabled, which could be exploited by malicious users to cause a denial of service.

The third flaw is due to an error in the file "drivers/char/drm/drm_stub.c" that does not properly validate "debug" sysfs permissions, which could be exploited by local attackers to bypass certain security restrictions and enable drm debugging.

Full Details.

More in Tux Machines

Mentor Embedded Linux gains cloud-based IoT platform

Mentor announced a “Mentor Embedded IoT Framework” platform that builds on top of Mentor Embedded Linux with cloud-based IoT cloud services ranging from device authentication and provisioning to monitoring and diagnostics. Mentor’s Mentor Embedded IoT Framework (MEIF) extends its Yocto Project based Mentor Embedded Linux (MEL) and Nucleus RTOS development platforms to provide cloud services for IoT device management. The platform mediates between these platforms and cloud service backends, including Amazon Web Services (AWS), Eclipse IoT, Microsoft Azure, and Siemens MindSphere. Read more

Bang & Olufsen’s RPi add-on brings digital life to old speakers

B&O and HiFiBerry have launched an open source, DIY “Beocreate 4” add-on for the Raspberry Pi that turns vintage speakers into digitally amplified, wireless-enabled smart speakers with the help of a 180-Watt 4-channel amplifier, a DSP, and a DAC. Bang & Olufsen has collaborated with HiFiBerry to create the open source, $189 Beocreate 4 channel amplifier kit. The 180 x 140 x 30mm DSP/DAC/amplifier board pairs with your BYO Raspberry Pi 3 with a goal of upcycling vintage passive speakers. Read more

Gemini PDA will ship with Android, but it also supports Debian, Ubuntu, Sailfish, and Postmarket OS (crowdfunding, work in progress)

The makers of the Gemini PDA plan to begin shipping the first units of their handheld computer to their crowdfunding campaign backers any day now. And while the folks at Planet Computer have been calling the Gemini PDA a dual OS device (with Android and Linux support) from the get go, it turns out the first units will actually just ship with Android. Read more

Red Hat: CO.LAB, Kubernetes/OpenShift, Self-Serving 'Study' and More