Feeds

Linux kernel cured of remote panic-attack bug

Get your BUG_ON

Top 5 reasons to deploy VMware with Tegile

Developers of the Linux kernel have patched a bug that allowed attackers to remotely crash a machine by sending it malicious Wi-Fi signals.

The flaw in the delBA handling of mac80211 has been fixed in version 2.6.32, the latest stable release of the Linux kernel. Various distributions of the open-source operating system have already acknowledged the issue and are expected to push out updates soon. Based on developer notes on the official Linux website, the vulnerability appears to have been introduced in February.

The flaw stemmed from faulty code that called the BUG_ON macro before various checks were performed. That raised the possibility of NULL being passed to TX/RX_STOP parameter, which in turn caused a kernel panic. The end result: an attacker within Wi-Fi range of a vulnerable machine might be able to effectively shut it down.

The bug was discovered by Johannes Berg, who found a separate flaw related to mac80211 that was fixed in the latest release. Details about both flaw are here and here. ®

Remote control for virtualized desktops

More from The Register

next story
Knock Knock tool makes a joke of Mac AV
Yes, we know Macs 'don't get viruses', but when they do this code'll spot 'em
Feds seek potential 'second Snowden' gov doc leaker – report
Hang on, Ed wasn't here when we compiled THIS document
Why weasel words might not work for Whisper
CEO suspends editor but privacy questions remain
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
BlackEnergy crimeware coursing through US control systems
US CERT says three flavours of control kit are under attack
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
New hybrid storage solutions
Tackling data challenges through emerging hybrid storage solutions that enable optimum database performance whilst managing costs and increasingly large data stores.
Mitigating web security risk with SSL certificates
Web-based systems are essential tools for running business processes and delivering services to customers.