Linux at risk from NULL security flaw | Internet News

Linux at risk from NULL security flaw

Aug 14, 2009
1 minute read

tux.jpg

From the

this is not a drill’

files:

Linux users take note: we’re all at risk from a kernel privilege escalation flaw. No it’s not the end of the world, that will lead to massive remote exploits and all Linux servers being pwnd. But it is something to be concerned about.

The flaw is a NULL pointer error that exists in all versions of the Linux kernel released since 2001. No that’s not a typo.

This is a flaw that potentially has been in Linux for eight years and has somehow escaped the ‘many eyes’ philosophy of finding security flaws. It has also somehow escaped the static analysis that is performed on the Linux kernel that is supposed to find such NULL pointer flaws.

“Tavis Ormandy and myself have recently found and investigated a Linux kernel vulnerability,” Security Researcher Julien Tinnes wrote in his advisory. “It affects all 2.4 and 2.6 kernels since 2001 on all architectures. We believe this is the public vulnerability affecting the greatest number of kernel versions.”

Linux founder Linus Torvalds, late Thursday committed a patch to the Linux kernel that will mitigate the issue – which is good. But considering that it takes time for such a patch to propagate into kernel builds used by the Linux distributions, there is cause for concern.

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.