logoalt Hacker News

miduilyesterday at 8:07 PM4 repliesview on HN

This again does not work under Android, at least in termux compiled with clang/gcc.


Replies

staticassertionyesterday at 8:21 PM

I assume because the rxrpc module is not loaded / provided and because unprivileged user namespaces are not allowed, which should be sufficient to mitigate. Curious if someone else has more details though.

jeroenhdyesterday at 10:43 PM

The exploit as posted contains x86 shellcode, so you'd need to drop in the appropriate shellcode to test if it really works.

Android wasn't vulnerable the last time, so far it's been a shining beacon of hope for proper SELinux configuration that I wish was more widely available in other places.

ronsoryesterday at 8:10 PM

Android has a lot of hardening and sandboxing that desktop Linux doesn't (and won't for UX reasons).

show 3 replies
pjmlpyesterday at 8:14 PM

Because Android is not Linux, as much as some pretend it is.

In fact, given the official public APIs, Google could replace the Linux kernel with a BSD, and userspace wouldn't notice, other than rooted devices, and the OEMs themselves baking their Android distro.

show 1 reply