Exploiting the unexploitable, Linux 2.6.30+/SELinux/RHEL5 test kernel 0day
lists.grok.org.uk
lists.grok.org.uk
It's a good thing this is a local exploit... humble fellow too...
ETA: I just tried this on a CentOS5 vmware image (2.6.18-92.1.22.el5) without SELinux and couldn't get it to work.
This exploit used a trivial root exploit to setup a deeper kernel level exploit, that can bypass SELinux, hide itself completely, etc.
for RHEL5 2.6.18 compile with:
cc -fno-stack-protector -DRHEL5_SUCKS -o exploit exploit.c
then just ./exploit Began port to RHEL5 2.6.18-157: 7/12/09 12:00PM
...
The buggy commit was backported to a RHEL5 test kernel on April 15th
(the latest test kernel is still vulnerable and likely without this
exploit being released, the code would have made it into the next
RedHat kernel update)
https://bugzilla.redhat.com/show_bug.cgi?id=495863
That bug report says the first test kernel with that 'fix' applied was kernel-2.6.18-148.el5.