[LUAU] no secure kernels

bbraun at sparcy.synack.net bbraun at sparcy.synack.net
Thu Jan 28 08:13:17 PST 1999


Just for those that don't keep up on the security mailing lists,
There is currently no stable kernel that is safe from local users
right now.
2.2.0 has a problem where under certain conditions doing an ldd on a
core file will reboot the machine.

And of course 2.0.* have the bug where a user can make the kernel
leak an arbitrary amount of memory and take all ports on a machine
and make them unusable.

This does not bode well for linux.  =(

I urge you all to upgrade to 2.2.1 when it comes out.  Look for it
in the next couple days.

Also, I would strongly recommend looking at Solar Designer's
secure linux patches.  This may or may not be for you, but take a
look at: http://www.false.com/security/linux/
Does some things to prevent stack execution (some saftey from
buffer overflow exploits) and the like.

Rob



More information about the LUAU mailing list