Linux Kernel SPARC Architecture Memory Mapped Virtual Address Validation Bug Lets Local Users Crash the System
|
|
SecurityTracker Alert ID: 1020119
|
|
SecurityTracker URL: http://securitytracker.com/id?1020119
|
|
CVE Reference: CVE-2008-2137
(Links to External Site)
|
Date: May 28 2008
|
Impact: Denial of service via local system
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): Sparc architecture; prior to 2.6.25.3
|
Description: A vulnerability was reported in the Linux Kernel. A local user can cause denial of service conditions.
A local user can exploit a flaw in the validation of memory mapped virtual address ranges to cause the kernel to crash.
Sparc-based systems are affected.
David Miller and Jan Lieskovsky reported this vulnerability.
|
Impact: A local user can cause the target system to crash.
|
Solution: The vendor has issued a fixed version (2.6.25.3).
|
Vendor URL: www.kernel.org/ (Links to External Site)
|
Cause: Input validation error
|
Underlying OS: Linux (Caldera/SCO), Linux (Conectiva), Linux (Debian), Linux (EnGarde), Linux (Gentoo), Linux (HP Secure OS), Linux (Immunix), Linux (Mandriva/Mandrake), Linux (Progeny Debian), Linux (Red Hat Enterprise), Linux (Red Hat Fedora), Linux (Red Hat Linux), Linux (SGI), Linux (Slackware), Linux (Sun), Linux (SuSE), Linux (Trustix), Linux (Turbo Linux), Linux (Ubuntu), Linux (Xandros)
|
|
Message History:
None.
|
Source Message Contents
|
|
|
[Original Message Not Available for Viewing]
|
|