HomeSecurityCommon zero-day vulnerability in Android and Linux allows root access

Common zero-day vulnerability in Android and Linux allows root access

Security researchers at Perception Point have uncovered a new zero-day vulnerability in the Linux kernel that affects both the Linux operating system and the Android mobile operating system. Successful exploitation of this flaw (CVE-2016-0728) gives attackers root access to the affected device.

Common zero-day vulnerability in Android and Linux allows root access

According to the researchers who discovered this flaw, the zero-day is a local privilege escalation vulnerability in the Linux kernel that stems from a reference leak in the keyring utility.

The Linux keyring installation stores login information in encrypted form, making it available to other applications and drivers when they need it.

As Perception Point developers explain, the keyring feature also gives applications the additional ability to experiment with cryptographic keys, and even replace them when necessary.

This process can be compromised and an attacker taking advantage of this unnecessary feature can trick the keyring application into executing malicious code in the kernel.

Security researchers have notified the Linux, which will develop patches in the coming days. The source code for the vulnerability is available on GitHub.

The vulnerability was introduced into the Linux kernel in 2012. Any Linux PC running version 3.8 or later of the Linux kernel is vulnerable, regardless of whether it is a 32-bit or 64-bit architecture.

All Android devices running KitKat or later are also affected, which currently accounts for about two-thirds of all Android devices. The zero-day also affects Android devices because Google built the Android OS on an older version of the Linux kernel.

Linux versions of the operating system that install SMEP (Supervisor Mode Execution Protection) and SMAP (Supervisor Mode Access Protection) make exploiting this vulnerability much more difficult. The same goes for Android with SELinux.

At the rate at which smartphone manufacturers and mobile phone companies are rolling out security updates for their devices, this zero-day is unlikely to go away anytime soon. However, things should move faster on desktops, where most Linux OSes come with an automatic update feature.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS