"udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic [...]"
There is barely any OS that are >= 4.5 (only CoreOS on the top of my head).
"udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic [...]"
There is barely any OS that are >= 4.5 (only CoreOS on the top of my head).
The bug is said to not be exploitable since Al Viro function change. This change happened in 3.19.
http://lxr.free-electrons.com/source/net/core/datagram.c?v=3...
http://lxr.free-electrons.com/source/net/core/datagram.c?v=4...
http://lxr.free-electrons.com/source/net/core/datagram.c?v=4...
I am just trying to completely understand the bug, I wonder if it really was unexploitable before the patch. Got any source for that?
EDIT: sorry, misunderstood your message / mixed up commits, I was looking into when 89c22d8c3b27 hit mainline, which causes the vulnerable code path.
Edit: Ubuntu's tracker is at https://people.canonical.com/~ubuntu-security/cve/2016/CVE-2...
No, ALL production OS backport security patches to their kernels. This bug was fixed in Debian 15 months ago and Debian stable kernel is way older than 4.5.
> "udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic [...]" > There is barely any OS that are >= 4.5 (only CoreOS on the top of my head).
Kernel version is meaningless, see above.
Most servers/business run on (not the latest) redhat/suse/debian/ubuntu and derivates. They dont have kernel versions that recent.