New Zero-Day Linux kernel vulnerability exploit posted

, posted: 15-Jul-2006 14:47

This recent SANS Handler's diary post says an exploit for a new Linux kernel vulnerability has been posted. The exploit provides privilege escalation and works on all 2.6.x kernels, although SANS says SELinux stops it from working.

Don't have many details yet, but SANS writes:

... the published exploit depends on the a.out support in the kernel (the CONFIG_BINFMT_AOUT has to be set), but the vulnerability can be exploited no matter if a.out is supported or not.

That doesn't make sense to me: so the a.out binary format has to be compiled into the kernel, but the exploit works even if a.out isn't supported. Huh?

