Linux Kernel x86_64 Kernel LDT 'ldt_desc' Buffer Overflow Vulnerability
BID:30351
Info
Linux Kernel x86_64 Kernel LDT 'ldt_desc' Buffer Overflow Vulnerability
| Bugtraq ID: | 30351 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-3247 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 22 2008 12:00AM |
| Updated: | Jul 25 2008 03:48AM |
| Credit: | This issue was disclosed in a SUSE advisory. |
| Vulnerable: |
S.u.S.E. openSUSE 11.0 Linux kernel 2.6.25 .9 Linux kernel 2.6.25 .8 Linux kernel 2.6.25 .7 Linux kernel 2.6.25 .6 Linux kernel 2.6.25 .5 Linux kernel 2.6.25 .10 Linux kernel 2.6.25 Linux kernel 2.6.25.4 Linux kernel 2.6.25.3 Linux kernel 2.6.25.2 Linux kernel 2.6.25.1 |
| Not Vulnerable: |
Linux kernel 2.6.25 .11 |
Discussion
Linux Kernel x86_64 Kernel LDT 'ldt_desc' Buffer Overflow Vulnerability
The Linux kernel is prone to a buffer-overflow vulnerability because the software fails to perform adequate boundary checks on user-supplied data on 64-bit computers.
A local attacker can exploit this issue to execute arbitrary code with kernel-level privileges. Successfully exploiting this issue will result in the complete compromise of affected computers. Failed exploit attempts will cause a denial-of-service condition.
Linux kernels 2.6.25 through 2.6.25.10 are affected.
The Linux kernel is prone to a buffer-overflow vulnerability because the software fails to perform adequate boundary checks on user-supplied data on 64-bit computers.
A local attacker can exploit this issue to execute arbitrary code with kernel-level privileges. Successfully exploiting this issue will result in the complete compromise of affected computers. Failed exploit attempts will cause a denial-of-service condition.
Linux kernels 2.6.25 through 2.6.25.10 are affected.
Exploit / POC
Linux Kernel x86_64 Kernel LDT 'ldt_desc' Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Linux Kernel x86_64 Kernel LDT 'ldt_desc' Buffer Overflow Vulnerability
Solution:
Fixes are available. Please see the references for more information.
Linux kernel 2.6.25.2
Linux kernel 2.6.25.3
Linux kernel 2.6.25.4
Linux kernel 2.6.25.1
Linux kernel 2.6.25 .9
Linux kernel 2.6.25 .10
Linux kernel 2.6.25
Linux kernel 2.6.25 .7
Linux kernel 2.6.25 .5
Linux kernel 2.6.25 .6
Linux kernel 2.6.25 .8
Solution:
Fixes are available. Please see the references for more information.
Linux kernel 2.6.25.2
-
Linux linux-2.6.25.11.tar.gz
http://www.kernel.org/pub/linux/kernel/v2.6/linux-2.6.25.11.tar.gz
Linux kernel 2.6.25.3
-
Linux linux-2.6.25.11.tar.gz
http://www.kernel.org/pub/linux/kernel/v2.6/linux-2.6.25.11.tar.gz
Linux kernel 2.6.25.4
-
Linux linux-2.6.25.11.tar.gz
http://www.kernel.org/pub/linux/kernel/v2.6/linux-2.6.25.11.tar.gz
Linux kernel 2.6.25.1
-
Linux linux-2.6.25.11.tar.gz
http://www.kernel.org/pub/linux/kernel/v2.6/linux-2.6.25.11.tar.gz
Linux kernel 2.6.25 .9
-
Linux linux-2.6.25.11.tar.gz
http://www.kernel.org/pub/linux/kernel/v2.6/linux-2.6.25.11.tar.gz
Linux kernel 2.6.25 .10
-
Linux linux-2.6.25.11.tar.gz
http://www.kernel.org/pub/linux/kernel/v2.6/linux-2.6.25.11.tar.gz
Linux kernel 2.6.25
-
Linux linux-2.6.25.11.tar.gz
http://www.kernel.org/pub/linux/kernel/v2.6/linux-2.6.25.11.tar.gz
Linux kernel 2.6.25 .7
-
Linux linux-2.6.25.11.tar.gz
http://www.kernel.org/pub/linux/kernel/v2.6/linux-2.6.25.11.tar.gz
Linux kernel 2.6.25 .5
-
Linux linux-2.6.25.11.tar.gz
http://www.kernel.org/pub/linux/kernel/v2.6/linux-2.6.25.11.tar.gz
Linux kernel 2.6.25 .6
-
Linux linux-2.6.25.11.tar.gz
http://www.kernel.org/pub/linux/kernel/v2.6/linux-2.6.25.11.tar.gz
Linux kernel 2.6.25 .8
-
Linux linux-2.6.25.11.tar.gz
http://www.kernel.org/pub/linux/kernel/v2.6/linux-2.6.25.11.tar.gz
References
Linux Kernel x86_64 Kernel LDT 'ldt_desc' Buffer Overflow Vulnerability
References:
References:
- Linux 2.6.25.11 Changelog (Linux Kernel)
- Linux kernel Homepage (kernel.org)
- openSUSE Homepage (SUSE)