avoid setting up anonymous pages into file mapping in kernel CVE-2015-3288

asked 2017-02-10

This vulnerability (CVSS v3 Base Score: 7.8 High) has been fixed in kernel 3.4.111 on March 21st '16 but Jolla1-2.1.0 is still on kernel and needs that patch to prevent local apps (from e.g. aptoide or apk_s/rpm_s from the web) from gaining root privileges.

edit 20170327: still not fixed in ea
edit 20170403: still not fixed in ea

I thought we were on 3.10

@kat6 no ,

Is there active exploit i can use?

@coderus The bad guys will have it, for sure ;) since this entered mitre on 2015/04/10 and was fixed Jul 6, 2015 with kernel 4.1.4 but appeared on web.nvd.nist.gov 10/16/2016 and Google Jan'17 marked critical... quite enough time.

kat6 is right, 2.1 uses kernel 3.10, at least on my Aqua Fish / Jolla C:

[nemo@Sailfish ~]$ uname -a
Linux Sailfish 3.10.49+0.0.66 #1 SMP PREEMPT Fri Jan 13 19:20:21 UTC 2017 armv7l armv7l armv7l GNU/Linux
jolla1 is on 3.4 and will stay there... most likely jollaC-kernel has this vulnerability, too. @ghling on JollaC you'll need at least 3.10.86 to have this patch included automatically!

