PaX 2.6 Kernel Patch Denial Of Service Vulnerability
BID:10264
Info
PaX 2.6 Kernel Patch Denial Of Service Vulnerability
| Bugtraq ID: | 10264 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 03 2004 12:00AM |
| Updated: | May 03 2004 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to ChrisR- <[email protected]>. |
| Vulnerable: |
The PaX Team PaX linux 2.6.5 Gentoo Linux 1.4 |
| Not Vulnerable: | |
Discussion
PaX 2.6 Kernel Patch Denial Of Service Vulnerability
PaX for 2.6 series Linux kernels has been reported prone to a local denial of service vulnerability. The issue is reported to present itself when PaX Address Space Layout Randomization Layout (ASLR) is enabled.
The vulnerability may be exploited by a local attacker to influence the kernel into an infinite loop.
PaX for 2.6 series Linux kernels has been reported prone to a local denial of service vulnerability. The issue is reported to present itself when PaX Address Space Layout Randomization Layout (ASLR) is enabled.
The vulnerability may be exploited by a local attacker to influence the kernel into an infinite loop.
Exploit / POC
PaX 2.6 Kernel Patch Denial Of Service Vulnerability
Michel Blomgren <[email protected]> has supplied the following proof of concept:
Michel Blomgren <[email protected]> has supplied the following proof of concept:
Solution / Fix
PaX 2.6 Kernel Patch Denial Of Service Vulnerability
Solution:
The vendor has released an upgrade to address this vulnerability.
Gentoo Linux has released advisory GLSA 200407-02 addressing this and other issues. Please see the referenced advisory for further information about this issue and information on upgrading packages using emerge.
The PaX Team PaX linux 2.6.5
Solution:
The vendor has released an upgrade to address this vulnerability.
Gentoo Linux has released advisory GLSA 200407-02 addressing this and other issues. Please see the referenced advisory for further information about this issue and information on upgrading packages using emerge.
The PaX Team PaX linux 2.6.5
-
The PaX Team pax-linux-2.6.5-200405011700.patch
http://pax.grsecurity.net/pax-linux-2.6.5-200405011700.patch
References
PaX 2.6 Kernel Patch Denial Of Service Vulnerability
References:
References:
- A small bug in PaX was found. (borg (ChrisR-))
- PaX Homepage (The PaX Team)
- PaX DoS proof-of-concept (Michel Blomgren
)