Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    A Look at Linux, Android Zero-Days and the Perils of Patches

    Written by

    Sean Michael Kerner
    Published January 24, 2016
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Some vulnerabilities have a bigger impact that others, and not every flaw that a researcher claims is critical represents an immediate risk to users.

      Case in point: security firm Perception Point’s recent disclosure of the CVE-2016-0728 vulnerability. Perception Point alleges that the zero-day flaw exposes tens of millions of Linux devices, including Android phones to the risk of exploitation. As it turns out, the risk is not quite as pronounced as indicated, and there are significantly more pressing security issues that Android users should likely be concerned about.

      The CVE-2016-0728 issue is a use-after-free memory corruption vulnerability that could potentially enable a local privilege escalation. Linux vendor Red Hat detailed in a customer note that the vulnerability requires a potential attacker to already have access to a system.

      “The attacker must be able to run custom code on the account; in the most common configuration, this requires them to have a login and shell account on the target system,” Red Hat wrote.

      The same day that Perception Point’s disclosure was made a patch to fix the issue was made to the upstream Linux kernel. There are no public reports of any Linux user or system being exploited by the issue.

      Now looking at Android, which uses Linux at its core, the risk is small in Google’s view, and it has also already patched the mainline of Android’s open-source code. Adrian Ludwig, Google’s Android Security lead, emphasized in a Google+ post that the impact to Android devices is smaller than what Perception Point reported.

      “We believe that no Nexus devices are vulnerable to exploitation by third-party applications,” Ludwig wrote. “Further, devices with Android 5.0 and above are protected, as the Android SELinux policy prevents third-party applications from reaching the affected code.”

      SELinux (Security Enhanced Linux) provides additional access controls on system processes, which can limit the potential risk of privilege-escalation-related attack attempts. Going a step further, the CVE-2016-0728 vulnerability was introduced into the Linux 3.8 kernel, which was first released in February 2013.

      “Many devices running Android 4.4 and earlier do not contain the vulnerable code introduced in Linux kernel 3.8, as those newer kernel versions [are] not common on older Android devices,” Ludwig added.

      So to recap: A Linux kernel privilege-escalation vulnerability was announced, an attacker would already need access to a system to exploit it and Android isn’t at much risk, thanks to SELinux. Oh, and there are patches out now, too.

      Although CVE-2016-0728 might not be much of a risk, when it comes to Android, the much larger risk isn’t unknown zero-days, but rather known issues that users have not yet patched on their own devices. Somewhat, ironically, on the same day (Jan. 19) that Perception Point disclosed the Linux flaw, Duo Security reported that according to its own analysis, 90 percent of Android devices are running outdated operating systems.

      Looking deeper into the numbers, Mike Hanley, program manager, Labs R&D, Duo Security, told eWEEK that 32 percent of the Android devices his firm sees run a version of Android 4 or below, meaning they lack security mechanisms such as address space layout randomization, or ASLR, a key feature that makes the exploitation of Stagefright vulnerabilities more difficult. Stagefright vulnerabilities, first publicly revealed in July 2015, exposed hundreds of millions of Android users to risk.

      Since September 2015, Google has patched 93 security vulnerabilities, including multiple Stagefright-related issues. Those patches have been made available to Google Nexus devices users, though other Android devices are not getting updates as fast. Hanley noted that security updates are currently landing faster on supported Nexus devices, and he hopes that it will lead to changes in how quickly security patches are deployed to users who are constrained by carrier and OEM testing requirements.

      “Some OEMs have landed one or more rounds of Stagefright patches on their handsets though the time delay was significant,” Hanley said.

      There are also countless millions of unsupported Android phones in use that won’t get any updates from OEMs or carriers that are also at risk from at least the 93 issues that Google has patched since September.

      While news of the latest zero-day flaw against Linux is interesting, it is a seemingly trivial footnote in the context of the larger issue of known vulnerabilities for which user devices have not been patched. The truth is that the there are so many known vulnerabilities that an attacker can easily exploit that a zero-day isn’t nearly quite as interesting, regardless of how easy or hard it might be to execute.

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×