CENTER.HU groups
CENTER.HU address

User:

Guest

www.center.hu / Archive / Security news / april, 2005 / Denial of service due to a vulnerability in the Linux kernel 

Denial of service due to a vulnerability in the Linux kernel

Denial of service due to a vulnerability in the Linux kernel

Madrid, April 4 2005 - Security Tracker has reported, at this site , a vulnerability discovered in Linux kernel futex functions that could allow local users to cause denial of service conditions.

The problem stems from the fact that certain functions of the Linux kernel futex search for environment data with ˝get_user()˝ calls while holding the ˝mmap_sem˝ function for reserving memory for reading. If the get_user() call fails while another thread is in ˝mmap˝, the system can block.

The functions affected are in the ´kernel/futex.c´ in Linux version 2.6. This vulnerability could be used by a local user to crash the system.

The fix for this error is available on the ˝Linux Kernel Mailinglist˝ page at: http://lkml.org/lkml/2005/2/22/185.

Oxygen3 24h-365d
by Panda Software


Back




Copyright © CENTER.HU Ltd, 2000-2010. All rights reserved

sitemap | privacy policy |

copyrights | new pages |

terms of purchase | contact us


PARTNERS: Computerworld.hu | GameStar.hu | PCWorld.hu | SG.hu | PC Guru | Hitel