Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Fri, 23 Dec 2022 10:19:00 -0500
From: Jeffrey Walton <noloader@...il.com>
To: oss-security@...ts.openwall.com
Subject: Re: Details on this supposed Linux Kernel ksmbd RCE

On Fri, Dec 23, 2022 at 8:22 AM Eric Biggers <ebiggers@...nel.org> wrote:
>
> On Fri, Dec 23, 2022 at 09:17:28AM +0100, Marcus Meissner wrote:
> >
> > tldr: I requested 5 CVEs for the new ZDI issues Josh and Jan referenced.
> >
> > long form:
> >
> > Nice surprise 1 day before Christmas.
>
> Note that these bugs were already fixed in upstream and all affected Long Term
> Support (LTS) kernels months ago.  So this is really only a "surprise" for
> people who choose to use known buggy and insecure kernels that don't follow LTS.

Comes to mind: https://thenewstack.io/design-system-can-update-greg-kroah-hartman-linux-security/

> Anyway, these sorts of bugs are totally predictable in a complex, new network
> filesystem server (ksmbd).  Personally I recommend not using ksmbd.

Jeff

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.