( trey | 2010. 10. 20., sze – 13:04 )

A Ksplice már javította:

CVE-2010-3904: Local privilege escalation vulnerability in RDS sockets.

The rds_page_copy_user function did not perform any access checks on
user-provided pointers before using unchecked __copy_*_user_inatomic
functions, which can be exploited by a local user to write to
arbitrary kernel memory and escalate privileges.

Ksplice update ID: ivj3vgrr

--
trey @ gépház