Slashdot Mirror


Android's Latest Update Doesn't Patch Major Security Flaw 'Dirty COW' (engadget.com)

The November Android security update is live and it fixes 15 critical vulnerabilities, but it doesn't patch a major Linux kernel exploit that can give hackers quick and complete access to devices running on Google's OS. From a report on Engadget: Researcher Phil Oester discovered the flaw (CVE-2016-5195) in October, though he believes it's existed since 2007. The exploit is known as "Dirty COW" because of its basis in copy-on-write systems (and maybe because that name is adorable). With this month's security update, Google did roll out a "supplemental" firmware fix for Dirty COW across Nexus and Pixel devices. Plus, Samsung released a patch for its devices this month, according to Threatpost. An official Android patch for the Dirty COW issue is expected to land in December.

23 comments

  1. My Grandma asked if she should be worried. by Anonymous Coward · · Score: 4, Insightful

    I told her to root her phone, get the source code and fix it herself.

    Problem solved.

    1. Re:My Grandma asked if she should be worried. by just+another+AC · · Score: 1

      I told her to root her phone,

      In Australia when you use root as a verb it means to procreate. (yes this is a problem given how "gaining root access" is a more common discussion)

      I now cannot get that image out of my head. Thanks for ruining my day.

    2. Re:My Grandma asked if she should be worried. by antdude · · Score: 1

      What did she say and did she do it? :P

      --
      Ant(Dude) @ Quality Foraged Links (AQFL.net) & The Ant Farm (antfarm.ma.cx / antfarm.home.dhs.org).
    3. Re:My Grandma asked if she should be worried. by Big+Hairy+Ian · · Score: 1

      What's the point only about 1% of devices will actually get the patch

      --

      Build a Man a Fire, and He'll Be Warm for a Day. Set a Man on Fire, and He'll Be Warm for the Rest of His Life.

  2. and maybe because that name is adorable by Anonymous Coward · · Score: 0

    i like to lick it and stick it

    1. Re:and maybe because that name is adorable by Anonymous Coward · · Score: 0

      You can just grab women by the pussy, our president-elect says it's perfectly OK. No problem at all, it's totally acceptable to walk up to random women and grab them by their vaginas. HOW COOL IS THAT? Welcome to America!

    2. Re:and maybe because that name is adorable by Anonymous Coward · · Score: 0

      You can only do that if you're a star. And you don't do it to random women, only the hot ones. Way cool.

  3. Fixed it is ... so why say it is not? by Anonymous Coward · · Score: 0

    So it is fixed but it is not fixed is this clickbait or what?

    1. Re:Fixed it is ... so why say it is not? by Anonymous Coward · · Score: 0

      It's a partial fix, with the full patch coming in December. Saw only two sites report this correctly until now.

  4. Is there an open source app utilizing it to root? by Anonymous Coward · · Score: 0

    Is there an open source app utilizing it to root?
    Since this exploit is in basically all android devices since the beginning (as well as many other embedded linux devices!) shouldn't it be straightforward to make a 'rootkit' using it to help people unlock/reflash the majority of devices out there, at least for userspace purposes (anything with trustzone or locked bootloaders would still be restricted on reboot/above supervisor level privileges.)

  5. RedHat patches by emil · · Score: 1

    RedHat released backported Dirty Cow patches for the 2.6.18 kernel in EL5 last Friday.

    Why isn't Google using a RedHat kernel in Android, and applying the backported updates to /boot and /system, around OEM drivers?

    Why is the kernel "untouchable" by Google on non-Nexus devices? It didn't have to be this way. RedHat certainly makes kernel updates work with 3rd-party drivers. Oracle ksplice can even apply them without a reboot.

  6. butthurt much? by Anonymous Coward · · Score: 0

    get off the butthurt bandwagon. like you never said anything perverted, that wasn't true, when hanging with your same sex friends? these people so outraged over dirty talk, it's insane. grow up. watch an edgy stand-up comic, you'll hear the same type of stuff, it's called being funny. people say things all the time to be funny, very little of what is said is based in reality.

    1. Re:butthurt much? by Curtman · · Score: 1

      For sure, we've all been there on the access Hollywood bus and said ridiculous things about having molested women.. WTF is wrong with your country?

  7. The Cow Meme by Calydor · · Score: 1

    All you Dirty COWs go moo.

    --
    -=This sig has nothing to do with my comment. Move along now=-
  8. Dear /. moderators by Anonymous Coward · · Score: 0

    Dear /. moderators. If the article has four paragraphs, it's probably written by someone that has no clue. There are links to four other publications in that article, and Endgadget brings zero value to this report.

  9. e mail marketing by Disparo+Digital · · Score: 0

    e mail marketing Turbine suas vendas com e-mail marketing e potencialize suas oportunidades de negócio!

  10. Non-story by The+MAZZTer · · Score: 1

    The flaw was discovered AFTER the patch was finalized. Until they invent time travel, there isn't much Google can do at that point. The next patch, which is the first one which will be finalized after the discovery of this flaw, will have the fix. That's really the best anyone can expect I'd think.

    1. Re:Non-story by Anonymous Coward · · Score: 0

      considering google have vastly harsher expectations for Apple and Microsoft when it comes to patching it is not unreasonable to expect google to at least be as fast as what they are demanding from their competitors. It just goes to show what hypocrites they are.

    2. Re:Non-story by Anonymous Coward · · Score: 0

      Waiting a month (or more) for a critical security patch is not good. I switched to Android from iOS recently, and I'm not impressed with security so far. I knew this could be a problem, but the lack of vendors caring is astonishing.

      Google choose linux and now it's time to keep up with it.