Linux Kernel Page Faults Using NUMA Local Denial of Service Vulnerability
BID:27556
Info
Linux Kernel Page Faults Using NUMA Local Denial of Service Vulnerability
| Bugtraq ID: | 27556 |
| Class: | Design Error |
| CVE: |
CVE-2007-4130 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 31 2008 12:00AM |
| Updated: | Mar 12 2008 03:31PM |
| Credit: | This issue was disclosed in a Red Hat security advisory. |
| Vulnerable: |
Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux AS 4 Redhat Desktop 4.0 Linux kernel 2.6.9 Linux kernel 2.6.8 rc3 Linux kernel 2.6.8 rc2 Linux kernel 2.6.8 rc1 Linux kernel 2.6.8 Linux kernel 2.6.7 rc1 Linux kernel 2.6.7 Linux kernel 2.6.6 rc1 Linux kernel 2.6.6 Linux kernel 2.6.5 Linux kernel 2.6.4 Linux kernel 2.6.3 Linux kernel 2.6.2 Linux kernel 2.6.1 -rc2 Linux kernel 2.6.1 -rc1 Linux kernel 2.6.1 Linux kernel 2.6 .10 Linux kernel 2.6 -test9-CVS Linux kernel 2.6 -test9 Linux kernel 2.6 -test8 Linux kernel 2.6 -test7 Linux kernel 2.6 -test6 Linux kernel 2.6 -test5 Linux kernel 2.6 -test4 Linux kernel 2.6 -test3 Linux kernel 2.6 -test2 Linux kernel 2.6 -test11 Linux kernel 2.6 -test10 Linux kernel 2.6 -test1 Linux kernel 2.6 Linux kernel 2.6.8.1 Avaya Voice Portal 4.1 Avaya Voice Portal 4.0 Avaya SIP Enablement Services 4.0 Avaya Messaging Storage Server MSS 3.0 Avaya Message Networking MN 3.1 Avaya Meeting Exchange 5.0 Avaya Intuity AUDIX LX 2.0 Avaya Communication Manager 5.0 Avaya Communication Manager 4.0 Avaya Communication Manager 3.1 Avaya Aura SIP Enablement Services 3.1.1 Avaya Aura SIP Enablement Services 5.0 Avaya Aura Application Enablement Services 4.0.1 Avaya Aura Application Enablement Services 4.1 Avaya AES 4.0 |
| Not Vulnerable: | |
Discussion
Linux Kernel Page Faults Using NUMA Local Denial of Service Vulnerability
The Linux kernel is prone to a local denial-of-service vulnerability because it fails to properly handle certain page faults when using NUMA (Non-Uniform Memory Access) methods.
Attackers can exploit this issue to trigger kernel crashes, denying service to legitimate users.
Linux kernel 2.6.9 and prior versions are vulnerable. This issue affects the Itanium architecture; other architectures may also be vulnerable.
The Linux kernel is prone to a local denial-of-service vulnerability because it fails to properly handle certain page faults when using NUMA (Non-Uniform Memory Access) methods.
Attackers can exploit this issue to trigger kernel crashes, denying service to legitimate users.
Linux kernel 2.6.9 and prior versions are vulnerable. This issue affects the Itanium architecture; other architectures may also be vulnerable.
Exploit / POC
Linux Kernel Page Faults Using NUMA Local Denial of Service Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Linux Kernel Page Faults Using NUMA Local Denial of Service Vulnerability
Solution:
This issue was addressed in Red Hat Linux 4 kernel 2.6.9-67. Please see the references for more information.
Solution:
This issue was addressed in Red Hat Linux 4 kernel 2.6.9-67. Please see the references for more information.
References
Linux Kernel Page Faults Using NUMA Local Denial of Service Vulnerability
References:
References: