Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Linux Kernel Security is Lacking
Jason Miller, 2005-02-02

Recent events have shown that the way security in the Linux kernel is handled is broken, and it needs to be fixed right now.

Comments Mode:
Linux Kernel Security is Lacking 2005-02-02
Anonymous (1 replies)
Linux Kernel Security is Lacking 2005-02-04
Anonymous (5 replies)
Linux Kernel Security is Lacking 2005-02-05
Anonymous
Linux Kernel Security is Lacking 2005-02-06
Anonymous
"The numbers" and (deliberate?) failure to undestand what linux is 2005-02-07
RedHat not Linux User. (1 replies)
Re: The "numbers" and (deliberate?) failure to undestand what linux is 2005-02-07
Jason V. Miller (Author) (1 replies)
Vendors and kernel security 2005-02-09
Anonymous
Linux Kernel Security is Lacking 2005-02-03
Anonymous (1 replies)
Linux Kernel Security is Lacking 2005-02-04
Jason V. Miller (Author)
Linux Kernel Security is Lacking 2005-02-03
Todd Knarr (1 replies)
Linux Kernel Security is Lacking 2005-02-04
Jason V. Miller (Author) (1 replies)
?To report a security problem in a component, it seems like a simple enough task to look up the component in MAINTAINERS and send the report to the maintainer of that component.?

As detailed in the referenced Bugtraq post (see the article), e-mail messages to individual contributors (Linus and Andrew) didn't even result in a *response* to the security researcher who reported the issue. This is unacceptable.

Additionally, this list doesn't appear exhaustive, and nor is it at all straightforward. For example. If I find a vulnerability in the page fault handler (a vulnerability in this section of the Linux kernel was recently released), who am I supposed to contact? I see no reference to anything with the word ?memory? (as in virtual memory) in it aside from ?MEMORY TECHNOLOGY DEVICES?, and nothing at all for ?virtual?. Aside from being cumbersome, this doesn't appear to work as you intend it to even at present.

FreeBSD and NetBSD (the two operating systems that I'm most familiar with) both have a dedicated security team. I don't see why the Linux kernel shouldn't have something similar. Sure, we're just talking about a kernel and not an entire operating system, but the Linux kernel is *everywhere*.

I don't think that having the individual maintainers responsible for handling security advisories, patching, correspondence, etc. makes sense. It doesn't appear scalable, or reliable.

A simple secure@ e-mail address and Linux kernel security team seems the right choice for this particular part of my discussion.; it's worked for some of the BSD-based operating systems for quite some time.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/296/30358#30358
Linux Kernel Security is Lacking 2005-02-05
Todd Knarr (1 replies)
Linux Kernel Security is Lacking 2005-02-09
Joe Borsits (1 replies)
Linux Kernel Security is Lacking 2005-02-09
Todd Knarr (1 replies)
Linux Kernel Security is Lacking 2005-02-10
Joe Borsits
Linux Kernel Security is Lacking 2005-02-03
Anonymous (1 replies)
Linux Kernel Security is Lacking 2005-02-04
Jason V. Miller (Author) (1 replies)
Linux Kernel Security is Lacking 2005-02-05
RVGeerligs
Really? 2005-02-03
Anonymous
I eagerly await... 2005-02-03
Anonymous (5 replies)
I eagerly await... 2005-02-03
Anonymous
I eagerly await... 2005-02-03
Anonymous (2 replies)
I eagerly await... 2005-02-04
Anonymous
I eagerly await... 2005-02-07
Anonymous
I eagerly await... 2005-02-04
Anonymous
I eagerly await... 2005-02-04
Anonymous (1 replies)
I eagerly await... 2005-02-09
Anonymous
Re: I eagerly await... 2005-02-04
Anonymous (1 replies)
Re: I eagerly await... 2005-02-04
Jason V. Miller
Computer Security is Oxymoron - FYI reading here: 2005-02-03
Anonymous (1 replies)
Computer Security is Oxymoron No Longer 2005-02-07
Kernel hacker
So, what now about kernel security? 2005-02-03
Anonymous (2 replies)
So, what now about kernel security? 2005-02-04
Jason V. Miller (Author) (2 replies)
Linux Kernel Security is Lacking 2005-02-04
TJ (1 replies)
Linux Kernel Security is Lacking 2005-02-04
Keshav Jha
Linux Kernel Security is Lacking 2005-02-05
Anonymous
OpenBSD slogan 2005-02-06
Anonymous
Linux Kernel Security is Lacking 2005-02-08
Anonymous (1 replies)
Linux Kernel Security is Lacking 2005-02-09
Anonymous
Linux Kernel Security is Lacking 2005-02-09
Anonymous
Discussed on linux-kernel 2005-02-09
Anonymous
security@kernel.org 2005-02-09
Anonymous
Linux Kernel Security is Lacking 2005-02-09
Anonymous
Linux Kernel Security is Lacking 2005-02-09
Anonymous
Contact the module developer? 2005-02-09
Anonymous
Linux Kernel Security is Lacking 2005-02-09
Anonymous
Linux Kernel Security is Lacking 2005-02-10
Khawar Nehal







 

Privacy Statement
Copyright 2009, SecurityFocus