Linux Kernel Proc dentry_unused Corruption Local Denial of Service Vulnerability
BID:18183
CVE-2006-2629 |Info
Linux Kernel Proc dentry_unused Corruption Local Denial of Service Vulnerability
| Bugtraq ID: | 18183 |
| Class: | Race Condition Error |
| CVE: |
CVE-2006-2629 |
| Remote: | No |
| Local: | Yes |
| Published: | May 31 2006 12:00AM |
| Updated: | May 31 2006 08:42PM |
| Credit: | Tony Griffiths <[email protected]> discovered this issue. |
| Vulnerable: |
Linux kernel 2.6.17 -rc5 Linux kernel 2.6.16 13 Linux kernel 2.6.16 .9 Linux kernel 2.6.16 .8 Linux kernel 2.6.16 .7 Linux kernel 2.6.16 .5 Linux kernel 2.6.16 .4 Linux kernel 2.6.16 .3 Linux kernel 2.6.16 .2 Linux kernel 2.6.16 .19 Linux kernel 2.6.16 .18 Linux kernel 2.6.16 .17 Linux kernel 2.6.16 .16 Linux kernel 2.6.16 .12 Linux kernel 2.6.16 .11 Linux kernel 2.6.16 .1 Linux kernel 2.6.16 -rc1 Linux kernel 2.6.16 Linux kernel 2.6.15 .6 Linux kernel 2.6.15 .4 Linux kernel 2.6.15 .3 Linux kernel 2.6.15 .2 Linux kernel 2.6.15 .1 Linux kernel 2.6.15 -rc6 Linux kernel 2.6.15 -rc5 Linux kernel 2.6.15 -rc4 Linux kernel 2.6.15 -rc3 Linux kernel 2.6.15 -rc2 Linux kernel 2.6.15 -rc1 Linux kernel 2.6.15 Linux kernel 2.6.15.5 |
| Not Vulnerable: | |
Discussion
Linux Kernel Proc dentry_unused Corruption Local Denial of Service Vulnerability
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a flaw in the 'proc' filesystem.
This vulnerability allows local users to cause a kernel panic, denying further service to legitimate users.
This issue affects Linux kernel versions 2.6.15 through 2.6.17-rc5 on multiprocessor computers running SMP kernels. Other kernel versions may also be affected.
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a flaw in the 'proc' filesystem.
This vulnerability allows local users to cause a kernel panic, denying further service to legitimate users.
This issue affects Linux kernel versions 2.6.15 through 2.6.17-rc5 on multiprocessor computers running SMP kernels. Other kernel versions may also be affected.
Exploit / POC
Linux Kernel Proc dentry_unused Corruption Local Denial of Service Vulnerability
The following exploit code is sufficient to demonstrate this issue:
The following exploit code is sufficient to demonstrate this issue:
Solution / Fix
Linux Kernel Proc dentry_unused Corruption Local Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
References
Linux Kernel Proc dentry_unused Corruption Local Denial of Service Vulnerability
References:
References:
- kernel.org Homepage. (Linux Kernel)
- PROBLEM: /proc (procfs) task exit race condition causes a kernel (Tony Griffiths
)