Close
  • Latest News
  • Artificial Intelligence
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    A Look at Linux, Android Zero-Days and the Perils of Patches

    By
    Sean Michael Kerner
    -
    January 24, 2016
    Share
    Facebook
    Twitter
    Linkedin
      Android Security

      Some vulnerabilities have a bigger impact that others, and not every flaw that a researcher claims is critical represents an immediate risk to users.

      Case in point: security firm Perception Point’s recent disclosure of the CVE-2016-0728 vulnerability. Perception Point alleges that the zero-day flaw exposes tens of millions of Linux devices, including Android phones to the risk of exploitation. As it turns out, the risk is not quite as pronounced as indicated, and there are significantly more pressing security issues that Android users should likely be concerned about.

      The CVE-2016-0728 issue is a use-after-free memory corruption vulnerability that could potentially enable a local privilege escalation. Linux vendor Red Hat detailed in a customer note that the vulnerability requires a potential attacker to already have access to a system.

      “The attacker must be able to run custom code on the account; in the most common configuration, this requires them to have a login and shell account on the target system,” Red Hat wrote.

      The same day that Perception Point’s disclosure was made a patch to fix the issue was made to the upstream Linux kernel. There are no public reports of any Linux user or system being exploited by the issue.

      Now looking at Android, which uses Linux at its core, the risk is small in Google’s view, and it has also already patched the mainline of Android’s open-source code. Adrian Ludwig, Google’s Android Security lead, emphasized in a Google+ post that the impact to Android devices is smaller than what Perception Point reported.

      “We believe that no Nexus devices are vulnerable to exploitation by third-party applications,” Ludwig wrote. “Further, devices with Android 5.0 and above are protected, as the Android SELinux policy prevents third-party applications from reaching the affected code.”

      SELinux (Security Enhanced Linux) provides additional access controls on system processes, which can limit the potential risk of privilege-escalation-related attack attempts. Going a step further, the CVE-2016-0728 vulnerability was introduced into the Linux 3.8 kernel, which was first released in February 2013.

      “Many devices running Android 4.4 and earlier do not contain the vulnerable code introduced in Linux kernel 3.8, as those newer kernel versions [are] not common on older Android devices,” Ludwig added.

      So to recap: A Linux kernel privilege-escalation vulnerability was announced, an attacker would already need access to a system to exploit it and Android isn’t at much risk, thanks to SELinux. Oh, and there are patches out now, too.

      Although CVE-2016-0728 might not be much of a risk, when it comes to Android, the much larger risk isn’t unknown zero-days, but rather known issues that users have not yet patched on their own devices. Somewhat, ironically, on the same day (Jan. 19) that Perception Point disclosed the Linux flaw, Duo Security reported that according to its own analysis, 90 percent of Android devices are running outdated operating systems.

      Looking deeper into the numbers, Mike Hanley, program manager, Labs R&D, Duo Security, told eWEEK that 32 percent of the Android devices his firm sees run a version of Android 4 or below, meaning they lack security mechanisms such as address space layout randomization, or ASLR, a key feature that makes the exploitation of Stagefright vulnerabilities more difficult. Stagefright vulnerabilities, first publicly revealed in July 2015, exposed hundreds of millions of Android users to risk.

      Since September 2015, Google has patched 93 security vulnerabilities, including multiple Stagefright-related issues. Those patches have been made available to Google Nexus devices users, though other Android devices are not getting updates as fast. Hanley noted that security updates are currently landing faster on supported Nexus devices, and he hopes that it will lead to changes in how quickly security patches are deployed to users who are constrained by carrier and OEM testing requirements.

      “Some OEMs have landed one or more rounds of Stagefright patches on their handsets though the time delay was significant,” Hanley said.

      There are also countless millions of unsupported Android phones in use that won’t get any updates from OEMs or carriers that are also at risk from at least the 93 issues that Google has patched since September.

      While news of the latest zero-day flaw against Linux is interesting, it is a seemingly trivial footnote in the context of the larger issue of known vulnerabilities for which user devices have not been patched. The truth is that the there are so many known vulnerabilities that an attacker can easily exploit that a zero-day isn’t nearly quite as interesting, regardless of how easy or hard it might be to execute.

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and contributor to several leading IT business web sites.
      Get the Free Newsletter!
      Subscribe to Daily Tech Insider for top news, trends & analysis
      This email address is invalid.
      Get the Free Newsletter!
      Subscribe to Daily Tech Insider for top news, trends & analysis
      This email address is invalid.

      MOST POPULAR ARTICLES

      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Applications

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      IT Management

      Intuit’s Nhung Ho on AI for the...

      James Maguire - May 13, 2022 0
      I spoke with Nhung Ho, Vice President of AI at Intuit, about adoption of AI in the small and medium-sized business market, and how...
      Read more
      Applications

      Kyndryl’s Nicolas Sekkaki on Handling AI and...

      James Maguire - November 9, 2022 0
      I spoke with Nicolas Sekkaki, Group Practice Leader for Applications, Data and AI at Kyndryl, about how companies can boost both their AI and...
      Read more
      Cloud

      IGEL CEO Jed Ayres on Edge and...

      James Maguire - June 14, 2022 0
      I spoke with Jed Ayres, CEO of IGEL, about the endpoint sector, and an open source OS for the cloud; we also spoke about...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2022 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×