[1] https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/lin...
[1] https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/lin...
"udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic [...]"
There is barely any OS that are >= 4.5 (only CoreOS on the top of my head).
Edit: Ubuntu's tracker is at https://people.canonical.com/~ubuntu-security/cve/2016/CVE-2...
Most servers/business run on (not the latest) redhat/suse/debian/ubuntu and derivates. They dont have kernel versions that recent.
The bug is said to not be exploitable since Al Viro function change. This change happened in 3.19.
http://lxr.free-electrons.com/source/net/core/datagram.c?v=3...
http://lxr.free-electrons.com/source/net/core/datagram.c?v=4...
http://lxr.free-electrons.com/source/net/core/datagram.c?v=4...
I am just trying to completely understand the bug, I wonder if it really was unexploitable before the patch. Got any source for that?
EDIT: sorry, misunderstood your message / mixed up commits, I was looking into when 89c22d8c3b27 hit mainline, which causes the vulnerable code path.
No, ALL production OS backport security patches to their kernels. This bug was fixed in Debian 15 months ago and Debian stable kernel is way older than 4.5.
> "udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic [...]" > There is barely any OS that are >= 4.5 (only CoreOS on the top of my head).
Kernel version is meaningless, see above.
- Linux git 4.4.0-72-generic #93-Ubuntu SMP Fri Mar 31 14:07:41 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux (Ubuntu 16.04, but I can probably switch to HWE) - Linux censored 3.10.0-514.6.1.el7.x86_64 #1 SMP Wed Jan 18 13:06:36 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux (CentOS 7.3.1611)
not really cool :/
happily I have no udp traffic and the AWS/internal firewall blocks all udp traffic by default.
Apparently xenial 4.4 is not affected.