Linux Kernel VFS Lookup Bug Lets Local Users Deny Service
|
|
SecurityTracker Alert ID: 1020739
|
|
SecurityTracker URL: http://securitytracker.com/id?1020739
|
|
CVE Reference: CVE-2008-3275
(Links to External Site)
|
Updated: Oct 20 2008
|
Original Entry Date: Aug 25 2008
|
Impact: Denial of service via local system
|
Fix Available: Yes
Exploit Included: Yes
Vendor Confirmed: Yes
|
Version(s): prior to 2.6.25.15
|
Description: A vulnerability was reported in the Linux Kernel. A local user can cause denial of service conditions.
A VFS lookup can create a child dentry for a directory that has been deleted, causing the UBIFS orphan area to fill up and overflow.
A local user can exploit this to cause denial of service conditions.
The vulnerability resides in 'fs/namei.c'.
Zoltan Sogor
reported this vulnerability.
|
Impact: A local user can cause denial of service conditions on the target system.
|
Solution: The vendor has issued a fix (2.4.36.8, 2.6.25.15).
The vendor's advisory is available at:
http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.36.8
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.15
|
Vendor URL: www.kernel.org/ (Links to External Site)
|
Cause: Resource error
|
Underlying OS: Linux (Caldera/SCO), Linux (Conectiva), Linux (Debian), Linux (EnGarde), Linux (Gentoo), Linux (HP Secure OS), Linux (Immunix), Linux (Mandriva/Mandrake), Linux (Progeny Debian), Linux (Red Hat Enterprise), Linux (Red Hat Fedora), Linux (Red Hat Linux), Linux (SGI), Linux (Slackware), Linux (Sun), Linux (SuSE), Linux (Trustix), Linux (Turbo Linux), Linux (Ubuntu), Linux (Xandros)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Mon, 25 Aug 2008 16:06:05 -0400
Subject: Linux Kernel
|
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.15
CVE-2008-3275
|
|