Re: CVE-2016-7117 Remote code execution vulnerability in kernel networking subsystem

2016-10-04 Thread Salvatore Bonaccorso
Hi, On Tue, Oct 04, 2016 at 11:54:12PM +0200, Jan Lühr wrote: > Hello, > Am 10/04/2016 um 07:57 PM schrieb Nicholas Luedtke: > > On 10/04/2016 11:40 AM, Felix Knecht wrote: > > > >> On 10/04/2016 06:38 PM, Jan Lühr wrote: > >>> CVE-2016-7117 was patched in Android today.I don't see much informati

Re: CVE-2016-7117 Remote code execution vulnerability in kernel networking subsystem

2016-10-04 Thread Jan Lühr
Hello, Am 10/04/2016 um 07:57 PM schrieb Nicholas Luedtke: > On 10/04/2016 11:40 AM, Felix Knecht wrote: > >> On 10/04/2016 06:38 PM, Jan Lühr wrote: >>> CVE-2016-7117 was patched in Android today.I don't see much information >>> right now. The title is rather frightening - the issue appears to be

Re: CVE-2016-7117 Remote code execution vulnerability in kernel networking subsystem

2016-10-04 Thread Nicholas Luedtke
On 10/04/2016 11:40 AM, Felix Knecht wrote: > On 10/04/2016 06:38 PM, Jan Lühr wrote: >> CVE-2016-7117 was patched in Android today.I don't see much information >> right now. The title is rather frightening - the issue appears to be urgent. > The following upstream kernel commit is referenced in t

Re: CVE-2016-7117 Remote code execution vulnerability in kernel networking subsystem

2016-10-04 Thread Felix Knecht
On 10/04/2016 06:38 PM, Jan Lühr wrote: > CVE-2016-7117 was patched in Android today.I don't see much information > right now. The title is rather frightening - the issue appears to be urgent. The following upstream kernel commit is referenced in the security bulletin: https://git.kernel.org/cgit

CVE-2016-7117 Remote code execution vulnerability in kernel networking subsystem

2016-10-04 Thread Jan Lühr
Hello, CVE-2016-7117 was patched in Android today.I don't see much information right now. The title is rather frightening - the issue appears to be urgent. Can you confirm, that common Debian installation are unaffected and cannot be taken over via CVE-2016-7117? If not, I'd like to shut down a f