Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Where do you see that Ubuntu isn't affected?


>Side note: we discovered that Ubuntu 24.04 does not re-randomize the ASLR of its sshd children (it is randomized only once, at boot time); we tracked this down to the patch below, which turns off sshd's rexec_flag. This is generally a bad idea, but in the particular case of this signal handler race condition, it prevents sshd from being exploitable: the syslog() inside the SIGALRM handler does not call any of the malloc functions, because it is never the very first call to syslog().

No mention on 22.04 yet.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: