OpenBSD local DOS and root exploit

KryptoBSD writes :

" On current OpenBSD systems, any local user (being or not in the wheel group) can fill the kernel file descriptors table, leading to a denial of service. Because of a flaw in the way the kernel checks closed file descriptors 0-2 when running a setuid program, it is possible to combine these bugs and earn root access by winning a race condition.

The following is research material from FozZy from Hackademy and Hackerz Voice newspaper ( ) and can be distributed modified or not if proper credits are given to them.

Patch 003 fixes this condition in OpenBSD 3.1, and Patch 021 fixes this condition in OpenBSD 3.0. See errata.html for more details.

  1. By Anonymous Coward () on

    Isn't this bug the same seen on freebsd about a month ago ?

    1. By Cindy_Montreal () on

      Yeah, OpenBSD ports over all the bugs, flaws, and other problems. Then fixes them.

      What would be nice, if in ports there was packages that contains nothing but bugs, flaws, security risks, and other problems. This way anyone who feels they need to install security problem could. :)

      1. By Anonymous Coward () on

  2. By Anonymous Coward () on

    I wonder if that vulnerability was one of the reasons for the recent wave of stripping the current tree from suid bits...

    1. By Anonymous Coward () on

      When I saw this notice, I thought I better zip on
      over to to get the patch.
      But this bug was found and fixed on May 8 so I did
      not need to do anything.


