Slashdot Mirror


Linux 2.4.24 Release Fixes Root Vulnerability

diegocgteleline.es writes "Linux Kernel 2.4.24 has been released and is available on kernel.org. It seems there's a bug in the mremap(2) system call, where a local user can get root privileges.The new version has been released only with the most important bugs fixed - the rest of the changes have been postponed (those changes include the XFS filesystem)."

4 of 436 comments (clear)

  1. Re:This is why I love free (as in beer) software.. by irc.goatse.cx+troll · · Score: 1, Troll

    You confuse Linux community with Open Source community. OpenBSD is also opensource, but that doesn't mean he announced the local vulns out there that would allow any user to bring down your server. You had to complain on the obsd mailinglist and have someone send you a patch, which is really pretty sad.

    --
    Pain lasts, kid. Its how you know you're alive. Sometimes I think this growing up thing is just pain management-TheMaxx
  2. Re:Can't Wait! by Anonymous Coward · · Score: 0, Troll

    yawn.....

    convinced of what you say?

    why don't you show us the info that has so-called convinced you.

    on the other hand mr. 578650....don't bother.

    oh and it's not that i'm bothered by pro/anti microsoft either way...(i'm typing this from xp)...it's just that your post almost insists that i give a shit.

    and i don't.

  3. Re:2.4.x? by mentin · · Score: 1, Troll

    Interesting. Yesterday we flamed MS for dropping support of Windows 98, which is 5 years old, and today we are proposing to drop support of 2 weeks old kernel.

    --
    MSDOS: 20+ years without remote hole in the default install
  4. Re:we got r00t, d00d!!! by parksie · · Score: 0, Troll

    Some patches would undo other patches and one of my friends ran Windows Update and it broke his ability to connect to the Internet.

    That's probably the most useful patch MS ever included in Windows Update.