Linux VMLinux Arbitrary Kernel Execution Denial of Service Vulnerability
BID:3570
Info
Linux VMLinux Arbitrary Kernel Execution Denial of Service Vulnerability
| Bugtraq ID: | 3570 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 21 2001 12:00AM |
| Updated: | Nov 21 2001 12:00AM |
| Credit: | This vulnerability was announced by Juergen Pabel <[email protected]> via Bugtraq on November 21, 2001. |
| Vulnerable: |
Linux kernel 2.4.11 Linux kernel 2.4.10 Linux kernel 2.4.9 Linux kernel 2.4.8 Linux kernel 2.4.7 Linux kernel 2.4.6 Linux kernel 2.4.5 Linux kernel 2.4.4 Linux kernel 2.4.3 Linux kernel 2.4.2 Linux kernel 2.4.1 Linux kernel 2.4 |
| Not Vulnerable: |
Linux kernel 2.4.15 Linux kernel 2.4.14 Linux kernel 2.4.13 Linux kernel 2.4.12 |
Discussion
Linux VMLinux Arbitrary Kernel Execution Denial of Service Vulnerability
Linux is a freely available Unix clone operating system. The Linux kernel was originally written by Linus Torvalds, and is maintained by public domain.
A problem with the Linux kernel makes it possible for local users to deny service to other users of the system. When a second instance of the kernel is executed from the command line, it is typically killed by the running kernel. However, in the 2.4.10 series, a second instance of the kernel crashes a running system.
This problem makes it possible for a local user to deny service to legitimate users of the system.
Linux is a freely available Unix clone operating system. The Linux kernel was originally written by Linus Torvalds, and is maintained by public domain.
A problem with the Linux kernel makes it possible for local users to deny service to other users of the system. When a second instance of the kernel is executed from the command line, it is typically killed by the running kernel. However, in the 2.4.10 series, a second instance of the kernel crashes a running system.
This problem makes it possible for a local user to deny service to legitimate users of the system.
Exploit / POC
Linux VMLinux Arbitrary Kernel Execution Denial of Service Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
Linux VMLinux Arbitrary Kernel Execution Denial of Service Vulnerability
Solution:
Upgrade to a 2.4.12 or later kernel.
Solution:
Upgrade to a 2.4.12 or later kernel.
References
Linux VMLinux Arbitrary Kernel Execution Denial of Service Vulnerability
References:
References: