Security issue in kernel-vserver (all versions)

Jan Rekorajski baggins at sith.mimuw.edu.pl
Thu Apr 27 12:03:37 CEST 2006


There is a serious security issue with all versions of linux-vserver.
All versions 2.0 and above are vulnerable.

Description:
Setting context capability (ccapabilities) gives rights to use
operations allowed by this capability to all users inside vserver.

All users of kernel-vserver are urged to upgrade to latest kernel from
CVS.

Fixed version of kernel-vserver packages will be available in ac-test
later today.

Jan
-- 
Jan Rękorajski            |  ALL SUSPECTS ARE GUILTY. PERIOD!
baggins<at>mimuw.edu.pl   |  OTHERWISE THEY WOULDN'T BE SUSPECTS, WOULD THEY?
BOFH, MANIAC              |                   -- TROOPS by Kevin Rubio


More information about the pld-devel-en mailing list