This week at LWN: A privilege escalation flaw in udev

Posted by Scott_Ruecker on May 5, 2009 9:09 PM EDT
LWN.net; By Jake Edge
Mail this story
Print this story

A vulnerability in udev, the user-space tool that manages the Linux /dev tree, has left unpatched systems vulnerable to a local root privilege escalation. Exploits are already circulating on the full-disclosure mailing list, so it is rather important for users and administrators to update their systems. The problem was caused by the way udev processes the messages it receives—certain kinds of messages, which could be generated by user processes, were not considered. That oversight led to the vulnerability.

Full Story

  Nav
» Read more about: Groups: Linux; Story Type: News Story

« Return to the newswire homepage

Subject Topic Starter Replies Views Last Post
This week at LWN, way old news azerthoth 6 746 May 6, 2009 1:36 PM

You cannot post until you login.