[CentOS] Heads up on local root escalation

Thu May 15 10:48:58 UTC 2014
Leon Fauster <leonfauster at googlemail.com>

Am 15.05.2014 um 12:31 schrieb Peter <peter at pajamian.dhs.org>:
> On 05/15/2014 09:22 PM, Leon Fauster wrote:
>> cite: "This issue does affect the versions of the Linux kernel packages as shipped
>> with Red Hat Enterprise Linux 6.2 AUS, Red Hat Enterprise Linux 6.3 EUS and Red Rat 
>> Enterprise MRG 2, and we are currently working on corrected kernel packages that 
>> address this issue."
> 
> That should not be an issue for CentOS as CentOS does not support old
> point releases.  The simple answer is if you update to the latest 6.x
> you are not vulnerable.
> 
> RedHat has to address this because they do have support for staying on a
> particular point release.


Peter, sure I am with you. Anyway, to complete the big picture its just 
an additional information and BTW I know people staying on older point 
releases for various reasons. There are several scenarios in the wild :-)

--
LF