Linux Kernel SEARCH_BINARY_HANDLER Local Denial of Service Vulnerability
BID:16320
Info
Linux Kernel SEARCH_BINARY_HANDLER Local Denial of Service Vulnerability
| Bugtraq ID: | 16320 |
| Class: | Design Error |
| CVE: |
CVE-2005-2708 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 28 2005 12:00AM |
| Updated: | Nov 13 2006 08:16PM |
| Credit: | Reported by blossom. |
| Vulnerable: |
Trustix Secure Linux 3.0 Trustix Secure Linux 2.2 Trustix Secure Enterprise Linux 2.0 Linux kernel 2.4.32 -pre2 Linux kernel 2.4.32 -pre1 Linux kernel 2.4.32 Linux kernel 2.4.31 -pre1 Linux kernel 2.4.31 Linux kernel 2.4.30 rc3 Linux kernel 2.4.30 rc2 Linux kernel 2.4.30 Linux kernel 2.4.29 -rc2 Linux kernel 2.4.29 -rc1 Linux kernel 2.4.29 Linux kernel 2.4.28 Linux kernel 2.4.27 -pre5 Linux kernel 2.4.27 -pre4 Linux kernel 2.4.27 -pre3 Linux kernel 2.4.27 -pre2 Linux kernel 2.4.27 -pre1 Linux kernel 2.4.27 Linux kernel 2.4.26 Linux kernel 2.4.25 Linux kernel 2.4.24 -ow1 Linux kernel 2.4.24 Linux kernel 2.4.23 -pre9 Linux kernel 2.4.23 -ow2 Linux kernel 2.4.23 Linux kernel 2.4.22 Linux kernel 2.4.21 pre7 Linux kernel 2.4.21 pre4 Linux kernel 2.4.21 pre1 Linux kernel 2.4.21 Linux kernel 2.4.20 Linux kernel 2.4.19 -pre6 Linux kernel 2.4.19 -pre5 Linux kernel 2.4.19 -pre4 Linux kernel 2.4.19 -pre3 Linux kernel 2.4.19 -pre2 Linux kernel 2.4.19 -pre1 Linux kernel 2.4.19 Linux kernel 2.4.18 pre-8 Linux kernel 2.4.18 pre-7 Linux kernel 2.4.18 pre-6 Linux kernel 2.4.18 pre-5 Linux kernel 2.4.18 pre-4 Linux kernel 2.4.18 pre-3 Linux kernel 2.4.18 pre-2 Linux kernel 2.4.18 pre-1 Linux kernel 2.4.18 x86 Linux kernel 2.4.18 Linux kernel 2.4.17 Linux kernel 2.4.16 Linux kernel 2.4.15 Linux kernel 2.4.14 Linux kernel 2.4.13 Linux kernel 2.4.12 Linux kernel 2.4.11 Linux kernel 2.4.10 Linux kernel 2.4.9 Linux kernel 2.4.8 Linux kernel 2.4.7 Linux kernel 2.4.6 Linux kernel 2.4.5 Linux kernel 2.4.4 Linux kernel 2.4.3 Linux kernel 2.4.2 Linux kernel 2.4.1 Linux kernel 2.4 .0-test9 Linux kernel 2.4 .0-test8 Linux kernel 2.4 .0-test7 Linux kernel 2.4 .0-test6 Linux kernel 2.4 .0-test5 Linux kernel 2.4 .0-test4 Linux kernel 2.4 .0-test3 Linux kernel 2.4 .0-test2 Linux kernel 2.4 .0-test12 Linux kernel 2.4 .0-test11 Linux kernel 2.4 .0-test10 Linux kernel 2.4 .0-test1 Linux kernel 2.4 |
| Not Vulnerable: |
Linux kernel 2.4.33 -pre1 |
Discussion
Linux Kernel SEARCH_BINARY_HANDLER Local Denial of Service Vulnerability
Linux kernel is susceptible to a local denial-of-service vulnerability.
This issue presents itself in the 'search_binary_handler' function of 'exec.c'.
This issue allows local users to crash the kernel due to a panic, denying service to legitimate users.
Linux kernel 2.4 versions on 64-bit x86 architectures prior to 2.4.33-pre1 are affected.
Linux kernel is susceptible to a local denial-of-service vulnerability.
This issue presents itself in the 'search_binary_handler' function of 'exec.c'.
This issue allows local users to crash the kernel due to a panic, denying service to legitimate users.
Linux kernel 2.4 versions on 64-bit x86 architectures prior to 2.4.33-pre1 are affected.
Exploit / POC
Linux Kernel SEARCH_BINARY_HANDLER Local Denial of Service Vulnerability
A proof of concept is available at the following location:
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=161925
A proof of concept is available at the following location:
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=161925
Solution / Fix
Linux Kernel SEARCH_BINARY_HANDLER Local Denial of Service Vulnerability
Solution:
The vendor has released kernel version 2.4.33-pre1 to address this issue.
Please see the referenced advisories for more information:
- Red Hat has released advisory RHSA-2006:0140-9 to address various issues in Red Hat Enterprise Linux 3.
- Red Hat has released advisory RHSA-2006:0190-5 to address this and other issues.
Linux kernel 2.4.27
Solution:
The vendor has released kernel version 2.4.33-pre1 to address this issue.
Please see the referenced advisories for more information:
- Red Hat has released advisory RHSA-2006:0140-9 to address various issues in Red Hat Enterprise Linux 3.
- Red Hat has released advisory RHSA-2006:0190-5 to address this and other issues.
Linux kernel 2.4.27
-
Trustix kernel-2.4.33.3-1tr.i586.rpm
Trustix Secure Linux 2.2
ftp://ftp.trustix.org/pub/trustix/updates -
Trustix kernel-BOOT-2.4.33.3-1tr.i586.rpm
Trustix Secure Linux 2.2
ftp://ftp.trustix.org/pub/trustix/updates -
Trustix kernel-doc-2.4.33.3-1tr.i586.rpm
Trustix Secure Linux 2.2
ftp://ftp.trustix.org/pub/trustix/updates -
Trustix kernel-smp-2.4.33.3-1tr.i586.rpm
Trustix Secure Linux 2.2
ftp://ftp.trustix.org/pub/trustix/updates -
Trustix kernel-source-2.4.33.3-1tr.i586.rpm
Trustix Secure Linux 2.2
ftp://ftp.trustix.org/pub/trustix/updates -
Trustix kernel-utils-2.4.33.3-1tr.i586.rpm
Trustix Secure Linux 2.2
ftp://ftp.trustix.org/pub/trustix/updates
References
Linux Kernel SEARCH_BINARY_HANDLER Local Denial of Service Vulnerability
References:
References:
- Bugzilla Bug 161925 ? CVE-2005-2708 user code panics kernel in exec.c (blossom)
- kernel.org Homepage. (Linux Kernel)
- RHSA-2006:0140-9 - kernel security update (RedHat)
- RHSA-2006:0190-5 - kernel security update (RedHat)
- Summary of changes from v2.4.32 to v2.4.33-pre1 (kernel.org)