Welcome! Log In Create A New Profile

Advanced

Widespread Android vulnerability due to Linux 3.6+

Posted by JoeyPogoPlugE02 
Widespread Android vulnerability due to Linux 3.6+
August 16, 2016 05:01PM
The reason I mention it is for all of us who buy cheap products running Android and never change over the OS (or in the case of my smartphone, can't).

Here is the link to a FoxNews (I'm not otherwise any fan of them) article: Linux flaw puts 1.4 billion Android devices at risk of spying attack, experts warn

=========
-= Cloud 9 =-
Re: Widespread Android vulnerability due to Linux 3.6+
August 16, 2016 06:53PM
Joey, many thanks for the info.
Re: Widespread Android vulnerability due to Linux 3.6+
August 16, 2016 07:17PM
Is this something we can fix on our own or do we need a patch from bodhi for the kernel?
you are required to append the following to /etc/sysctl.conf:

net.ipv4.tcp_challenge_ack_limit = 999999999

Once done, use sysctl -p to activate the new rule. You need to perform root to do this.

https://thehackernews.com/2016/08/linux-tcp-packet-hacking.html
Re: Widespread Android vulnerability due to Linux 3.6+
August 17, 2016 01:05AM
feas,

> Is this something we can fix on our own or do we
> need a patch from bodhi for the kernel?

This problem was fixed in 4.7. So work around needed for kernel 4.6.x

----------------------------------------------------------
EDITED: to correct info for version effected.

-bodhi
===========================
Forum Wiki
bodhi's corner (buy bodhi a beer)



Edited 1 time(s). Last edit at 08/17/2016 04:45PM by bodhi.
Re: Widespread Android vulnerability due to Linux 3.6+
August 17, 2016 01:08AM
Re: Widespread Android vulnerability due to Linux 3.6+
August 17, 2016 04:15AM
as much as i adore Android, it should only ever be considered an "entertainment system" not an "operating system"

@bodhi & all
The vector vulnerability exists in all kernels from 3.6 upwards, so it is best to add the "fix" outlined above to all version above 3.6 until a new patched kernel is released upstream.



Edited 1 time(s). Last edit at 08/17/2016 04:21AM by Gravelrash.
Re: Widespread Android vulnerability due to Linux 3.6+
August 17, 2016 05:27AM
Gravelrash Wrote:
-------------------------------------------------------
> as much as i adore Android, it should only ever be
> considered an "entertainment system" not an
> "operating system"
>
> @bodhi & all
> The vector vulnerability exists in all kernels
> from 3.6 upwards, so it is best to add the "fix"
> outlined above to all version above 3.6 until a
> new patched kernel is released upstream.


thanks!
Re: Widespread Android vulnerability due to Linux 3.6+
August 17, 2016 10:57AM
@ all: I agree, you said it better than I could :-)

=========
-= Cloud 9 =-
Re: Widespread Android vulnerability due to Linux 3.6+
August 17, 2016 04:43PM
Indeed, thanks for checking Gravelrash.

https://security-tracker.debian.org/tracker/CVE-2016-5696

It was fixed in kernel 4.7

-bodhi
===========================
Forum Wiki
bodhi's corner (buy bodhi a beer)
Re: Widespread Android vulnerability due to Linux 3.6+
August 17, 2016 06:12PM
I was never worried in the least about the Debian installs here.

Androids though, never inspired my faith, so I keep them offline for the most part. Access home cloud storage and leave it at that.

There's a good quote from my last Computer Science professor: the probability you're being watched is directly proportional to the stupidity of your actions. -edit- and the rules applied to him as well :-D

=========
-= Cloud 9 =-



Edited 1 time(s). Last edit at 08/21/2016 06:21PM by JoeyPogoPlugE02.
Author:

Your Email:


Subject:


Spam prevention:
Please, enter the code that you see below in the input field. This is for blocking bots that try to post this form automatically. If the code is hard to read, then just try to guess it right. If you enter the wrong code, a new image is created and you get another chance to enter it right.
Message: