You are Here:
Linux Lite 6.6 FINAL Released - Support for 22 Languages Added - See Release Announcement Section



Linux Kernel Privilege Escalation Flaw Vulnerabillity CVE-2016-0728

Author (Read 4745 times)

0 Members and 1 Guest are viewing this topic.

Re: Linux Kernel Privilege Escalation Flaw Vulnerabillity CVE-2016-0728
« Reply #11 on: January 21, 2016, 11:01:28 AM »
 

justme2

  • PayPal Supporter
  • Forum Regular
  • *****
  • 201
    Posts
  • Reputation: 25
  • Linux Lite Member
    • View Profile

  • CPU: Intel i5 vPro

  • MEMORY: 8Gb

  • VIDEO CARD: Intel
Got a segmentation fault when running it so not going to spend forever analyzing this, was just curious. Vuln requires physical access to your pc. So if you have a friend who's a wizard on the command line, keep him/her away from your pc :)

To update:

Code: [Select]
sudo apt-get install linux-image-3.13.0-76-generic linux-headers-3.13.0-76-generic
Reboot.

Lite Tweaks, Kernel Removal, remove all other 3.13 kernels.

Installing Kernel 3.13.0-76 caused panic, my panic not kernel panic :-) as my wifi, wireless mouse, external sound card and DVB-T adapter all stopped working! However, all was not lost as I soon found a simple way to restore the earlier working kernel which brought the hardware back to life. So what I do not understand is will this new found vulnerability ever be removed from older kernels or do users of older hardware have to live with it and not progress to newer versions of Linux Lite with newer kernels?


1) Lenovo T520 i5 LL3.8 8GB ram, fast & stable
2) Medion P4 32bit LL3.8 1GB ram, quite fast & stable
3) eeePC 901 32bit LL3.8 1GB ram, fast & stable
4) eeePC 701 32bit LL3.8 1GB ram, slower & stable but small and light enough to travel with me to New Zealand when visiting family in Blenheim.
 

Re: Linux Kernel Privilege Escalation Flaw Vulnerabillity CVE-2016-0728
« Reply #10 on: January 20, 2016, 02:40:05 AM »
 

Jerry

  • Linux Lite Creator
  • Administrator
  • Platinum Level Poster
  • *****
  • 8777
    Posts
  • Reputation: 801
  • Linux Lite Member
    • View Profile
    • Linux Lite OS

  • CPU: Intel Core i9-10850K CPU @ 3.60GHz

  • MEMORY: 32Gb

  • VIDEO CARD: nVidia GeForce GTX 1650

  • Kernel: 5.x
Got a segmentation fault when running it so not going to spend forever analyzing this, was just curious. Vuln requires physical access to your pc. So if you have a friend who's a wizard on the command line, keep him/her away from your pc :)

To update:

Code: [Select]
sudo apt-get install linux-image-3.13.0-76-generic linux-headers-3.13.0-76-generic
Reboot.

Lite Tweaks, Kernel Removal, remove all other 3.13 kernels.

Code: [Select]
linux (3.13.0-76.120) trusty; urgency=low

  [ Upstream Kernel Changes ]

  * KEYS: Fix keyring ref leak in join_session_keyring()
    - LP: #1534887
    - CVE-2016-0728

 -- Luis Henriques <[email protected]>  Mon, 18 Jan 2016 09:54:03 +0000
« Last Edit: January 20, 2016, 03:09:50 AM by Jerry »
 

Re: Linux Kernel Privilege Escalation Flaw Vulnerabillity CVE-2016-0728
« Reply #9 on: January 19, 2016, 08:38:13 PM »
 

tomt

  • PayPal Supporter
  • Forum Regular
  • *****
  • 129
    Posts
  • Reputation: 13
    • View Profile

  • MEMORY: 8Gb
After reading Perception Point it looks like 3.8 and up is vulnerable. If this has not been exploited before, you can bet the chances are good it will be now.
 

Re: Linux Kernel Privilege Escalation Flaw Vulnerabillity CVE-2016-0728
« Reply #8 on: January 19, 2016, 04:20:53 PM »
 

Jerry

  • Linux Lite Creator
  • Administrator
  • Platinum Level Poster
  • *****
  • 8777
    Posts
  • Reputation: 801
  • Linux Lite Member
    • View Profile
    • Linux Lite OS

  • CPU: Intel Core i9-10850K CPU @ 3.60GHz

  • MEMORY: 32Gb

  • VIDEO CARD: nVidia GeForce GTX 1650

  • Kernel: 5.x
 

Re: Linux Kernel Privilege Escalation Flaw Vulnerabillity CVE-2016-0728
« Reply #7 on: January 19, 2016, 04:02:54 PM »
 

Jerry

  • Linux Lite Creator
  • Administrator
  • Platinum Level Poster
  • *****
  • 8777
    Posts
  • Reputation: 801
  • Linux Lite Member
    • View Profile
    • Linux Lite OS

  • CPU: Intel Core i9-10850K CPU @ 3.60GHz

  • MEMORY: 32Gb

  • VIDEO CARD: nVidia GeForce GTX 1650

  • Kernel: 5.x
Kernel numbering folks:

3.6 3.7 3.8 3.9 3.10 3.11 3.12 3.13......
 

Re: Linux Kernel Privilege Escalation Flaw Vulnerabillity CVE-2016-0728
« Reply #6 on: January 19, 2016, 03:04:41 PM »
 

Wirezfree

  • PayPal Supporter
  • Platinum Level Poster
  • *****
  • 1484
    Posts
  • Reputation: 405
  • Linux Lite "Advocate"
    • View Profile

  • CPU: i7-4790S

  • MEMORY: 16Gb

  • VIDEO CARD: Intel HD4600 (Integrated)
It's been there 3 years, and is there any evidence of this being exploited.??
Upgrades WIP 2.6 to 2.8 - (6 X 2.6 to 2.8 completed on: 20/02/16 All O.K )
Linux Lite 3.0 Humming on a ASRock N3070 Mobo ~ btrfs RAID 10 Install on 4 Disks :)

Computers Early days:
ZX Spectrum(1982) , HP-150 MS-DOS(1983) , Amstrad CPC464(1984) ,  BBC Micro B+64(1985) , My First PC HP-Vectra(1987)
 

Re: Linux Kernel Privilege Escalation Flaw Vulnerabillity CVE-2016-0728
« Reply #5 on: January 19, 2016, 01:40:15 PM »
 

avj

  • Gold Level Poster
  • *******
  • 530
    Posts
  • Reputation: 110
  • Linux Lite Member
    • View Profile

  • CPU: Dual core Intel Pentium D 2.80GHz

  • MEMORY: 2Gb

  • VIDEO CARD: AMD/ATI RC410 Radeon Xpress 200/1100
I may be wrong, but it looks to me that you should be OK as long as you only use the software in the regular repositories that come with the system. It is my opinion for the most part that this kind of threat comes into play when you download proprietary or some other unapproved software.  Open source software allows peer review of the code and makes it much harder for an exploit to slip through.
“I have not failed. I’ve just found 10,000 ways that won’t work.” - Thomas Edison
 

Re: Linux Kernel Privilege Escalation Flaw Vulnerabillity CVE-2016-0728
« Reply #4 on: January 19, 2016, 12:52:52 PM »
 

tomt

  • PayPal Supporter
  • Forum Regular
  • *****
  • 129
    Posts
  • Reputation: 13
    • View Profile

  • MEMORY: 8Gb
According to the PC article as I read it, it starts with kernel 3.8. "The Linux kernel is the core of all Linux-based operating systems, including Android. Its keyring facility provides a way for applications to store sensitive information such as authentication and encryption keys inside the kernel, where other user-space applications cannot access it." I did not see a mention that anything above that kernel would not be affected."According to them, the vulnerability was introduced in kernel version 3.8, released in Feb. 2013".  I could be wrong but that is how I understand it to read. The fact that it is now appearing after all this time still supports my theory for the need to add an anti-virus protection to any distro. They also mentioned in the article that some kernels will be affected for quite some time.
« Last Edit: January 19, 2016, 01:20:52 PM by tomt »
 

Re: Linux Kernel Privilege Escalation Flaw Vulnerabillity CVE-2016-0728
« Reply #3 on: January 19, 2016, 12:14:16 PM »
 

avj

  • Gold Level Poster
  • *******
  • 530
    Posts
  • Reputation: 110
  • Linux Lite Member
    • View Profile

  • CPU: Dual core Intel Pentium D 2.80GHz

  • MEMORY: 2Gb

  • VIDEO CARD: AMD/ATI RC410 Radeon Xpress 200/1100
From the posted articles it appears that someone may have to have physical access to the computer.  It also seems that it takes at least 30 minutes to pull off on a machine with Intel Core i7-5500 CPU, according to the detailed analysis found in the following link.

http://perception-point.io/2016/01/14/analysis-and-exploitation-of-a-linux-kernel-vulnerability-cve-2016-0728/
“I have not failed. I’ve just found 10,000 ways that won’t work.” - Thomas Edison
 

Re: Linux Kernel Privilege Escalation Flaw Vulnerabillity CVE-2016-0728
« Reply #2 on: January 19, 2016, 10:56:22 AM »
 

firenice03

  • Rockin' the FREE World
  • Global Moderator
  • Platinum Level Poster
  • *****
  • 1848
    Posts
  • Reputation: 284
  • Linux Lite Member
    • View Profile

  • CPU: AMD E2//Atom X5//AMD Phenom II X2

  • MEMORY: 4Gb

  • VIDEO CARD: AMD Mullin Radeon R2//Intel//AMD/ATI RS880

  • Kernel: 5.x

Need to see this, and I thought we were fine without the need the need for an anti-virus program.
Linux kernel flaw threatens millions of PCs, servers, and Android devices _ PCWorld.html

Adding a Link for folks:
http://www.pcworld.com/article/3023870/security/linux-kernel-flaw-endangers-millions-of-pcs-servers-and-android-devices.html

http://www.networkworld.com/article/3023866/linux-kernel-flaw-endangers-millions-of-pcs-servers-and-android-devices.html#tk.rss_security

It looks like per the article, affected Kernel is 3.8 and up... Guess its good that LL2.8 beta is at kernel 3.19??..??
But if folks have updated the kernel, they want to be informed..
« Last Edit: January 19, 2016, 10:58:54 AM by firenice03 »
LL4.8 UEFI 64 bit ASUS E402W - AMD E2 (Quad) 1.5Ghz  - 4GB - AMD Mullins Radeon R2
LL5.8 UEFI 64 bit Test UEFI Kangaroo (Mobile Desktop) - Atom X5-Z8500 1.44Ghz - 2GB - Intel HD Graphics
LL4.8 64 bit HP 6005- AMD Phenom II X2 - 8GB - AMD/ATI RS880 (HD4200)
LL3.8 32 bit Dell Inspiron Mini - Atom N270 1.6Ghz - 1GB - Intel Mobile 945GSE Express  -- Shelved
BACK LL5.8 64 bit Dell Optiplex 160 (Thin) - Atom 230 1.6Ghz - 4GB-SiS 771/671 PCIE VGA - Print Server
Running Linux Lite since LL2.2
 

Linux Kernel Privilege Escalation Flaw Vulnerabillity CVE-2016-0728
« Reply #1 on: January 19, 2016, 10:41:40 AM »
 

tomt

  • PayPal Supporter
  • Forum Regular
  • *****
  • 129
    Posts
  • Reputation: 13
    • View Profile

  • MEMORY: 8Gb

Need to see this, and I thought we were fine without the need the need for an anti-virus program.
Linux kernel flaw threatens millions of PCs, servers, and Android devices _ PCWorld.html
« Last Edit: February 14, 2016, 11:40:22 PM by Jerry »
 

 

-->
X Close Ad

Linux Lite 6.6 FINAL Released - Support for 22 Languages Added - See Release Announcement Section