doorsoft
2016-10-22 17:10 deepin
uname -a
4.4.0-2-deepin-amd64 #1 SMP Deepin 4.4.6-4 (2016-07-01) x86_64 GNU/Linux
uname -mrs
Linux 4.4.0-2-deepin-amd64 x86_64
4.4.0-2-deepin-amd64 #1 SMP Deepin 4.4.6-4 (2016-07-01) x86_64 GNU/Linux
uname -mrs
Linux 4.4.0-2-deepin-amd64 x86_64
Reply Like 0 View the author
I tried to compile the kernel from sources and with my big surprise i saw this:
Wtf is going on? Why the Deepin Kernel is based on 4.4-rc6 dropped long, long time ago? The kernel need instant updates and security fixes ASAP.
***UPDATE 23/10/2016***: i found the kernel is vulnerable to really old and patched exploit like the one related to: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4557 patched 5 month ago.
Read here: https://www.reddit.com/r/linux/c ... _de_but_0_security/
***UPDATE 23/10/2016***
Actually they have a wrong master branch old and outdated, the new one is the 4.4-02 now based on 4.4.26. The PoCs were tested on the actually .4.0-2-deepin-amd64 #1 SMP Deepin 4.4.6-4 (2016-07-01) x86_64 GNU/Linux. The Fix has been released and will be pushed soon. Thank you all for the sharing