Linux Kernel Driver Fault Handler 'mmap.c' Local Denial of Service Vulnerability
BID:27705
Info
Linux Kernel Driver Fault Handler 'mmap.c' Local Denial of Service Vulnerability
| Bugtraq ID: | 27705 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0007 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 08 2008 12:00AM |
| Updated: | Jan 08 2009 08:32PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
VMWare ESX Server 3.0.2 VMWare ESX Server 3.0.1 VMWare ESX Server 2.5.5 VMWare ESX Server 2.5.4 VMWare ESX Server 3.5 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 lpia Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server 9 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9 Redhat Linux Advanced Workstation 2.1 for the Ita 2.1 IA64 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Enterprise Linux 5 Server Redhat Desktop 4.0 Redhat Desktop 3.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Linux kernel 2.6.24 -rc5 Linux kernel 2.6.24 -rc4 Linux kernel 2.6.24 -rc3 Linux kernel 2.6.23 .7 Linux kernel 2.6.23 .6 Linux kernel 2.6.23 .5 Linux kernel 2.6.23 .4 Linux kernel 2.6.23 .3 Linux kernel 2.6.23 .2 Linux kernel 2.6.23 -rc2 Linux kernel 2.6.23 -rc1 Linux kernel 2.6.23 Linux kernel 2.6.24-rc2 Linux kernel 2.6.24-rc1 Linux kernel 2.6.23.10 Linux kernel 2.6.23.1 Linux kernel 2.6.23.09 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Voice Portal 4.1 Avaya Voice Portal 4.0 Avaya Voice Portal 3.0 Avaya SIP Enablement Services 4.0 Avaya SES 3.1.2 Avaya SES 3.1.1 Avaya SES 4.0 Avaya SES 3.1 Avaya SES 3.0 Avaya Messaging Storage Server MSS 3.0 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 3.1 Avaya Message Networking MN 3.1 Avaya Message Networking 3.1 Avaya Intuity AUDIX LX 2.0 Avaya EMMC 1.021 Avaya EMMC 1.017 Avaya Communication Manager 5.0 Avaya Communication Manager 4.0 Avaya Communication Manager 3.1 Avaya Communication Manager 3.0 Avaya Aura SIP Enablement Services 3.1.1 Avaya Aura SIP Enablement Services 5.0 Avaya Aura SIP Enablement Services 3.1 Avaya Aura SIP Enablement Services 3.0 Avaya AES 4.2 Avaya AES 4.0 |
| Not Vulnerable: |
Linux kernel 2.6.24 .1 |
Discussion
Linux Kernel Driver Fault Handler 'mmap.c' Local Denial of Service Vulnerability
The Linux kernel is prone to a local denial-of-service vulnerability because it fails to properly bounds-check certain fault handlers for device drivers.
Attackers can exploit this issue to trigger kernel crashes, denying service to legitimate users. Given the nature of this issue, attackers may also be able to execute arbitrary code, but this has not been confirmed.
Versions prior to Linux kernel 2.6.24.1 are vulnerable.
The Linux kernel is prone to a local denial-of-service vulnerability because it fails to properly bounds-check certain fault handlers for device drivers.
Attackers can exploit this issue to trigger kernel crashes, denying service to legitimate users. Given the nature of this issue, attackers may also be able to execute arbitrary code, but this has not been confirmed.
Versions prior to Linux kernel 2.6.24.1 are vulnerable.
Exploit / POC
Linux Kernel Driver Fault Handler 'mmap.c' Local Denial of Service Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Linux Kernel Driver Fault Handler 'mmap.c' Local Denial of Service Vulnerability
Solution:
This issue was addressed in Linux kernel 2.6.24.1. Please see the references for more information.
Linux kernel 2.6.23.1
Linux kernel 2.6.24-rc2
Linux kernel 2.6.23 .5
Linux kernel 2.6.23
Linux kernel 2.6.23 -rc1
Linux kernel 2.6.23 .7
Linux kernel 2.6.23 .2
Linux kernel 2.6.23 .3
Linux kernel 2.6.23 -rc2
Linux kernel 2.6.23 .6
Linux kernel 2.6.24 -rc3
Linux kernel 2.6.24 -rc5
Linux kernel 2.6.24 -rc4
Solution:
This issue was addressed in Linux kernel 2.6.24.1. Please see the references for more information.
Linux kernel 2.6.23.1
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.24-rc2
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.23 .5
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.23
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.23 -rc1
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.23 .7
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.23 .2
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.23 .3
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.23 -rc2
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.23 .6
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.24 -rc3
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.24 -rc5
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
Linux kernel 2.6.24 -rc4
-
Linux patch-2.6.24.1.bz2
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.24.1.bz2
References
Linux Kernel Driver Fault Handler 'mmap.c' Local Denial of Service Vulnerability
References:
References:
- Linux 2.6.24.1 Changelog (Kernel.org)
- [USN-618-1] Linux kernel vulnerabilities (Ubuntu)
- ASA-2008-225 kernel security and bug fix update (RHSA-2008-0237) (Avaya)
- Avaya Security Advisory ASA-2008-203 (Avaya)
- RHSA-2008:0211-8 kernel security and bug fix update (Red Hat)
- RHSA-2008:0233-10 kernel security and bug fix update (Red Hat)
- RHSA-2008:0237-10 kernel security and bug fix update (Red Hat)