Linux Kernel 'tun_chr_pool()' NULL Pointer Dereference Vulnerability
BID:35724
Info
Linux Kernel 'tun_chr_pool()' NULL Pointer Dereference Vulnerability
| Bugtraq ID: | 35724 |
| Class: | Design Error |
| CVE: |
CVE-2009-1897 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 17 2009 12:00AM |
| Updated: | Apr 13 2015 10:12PM |
| Credit: | Christian Borntraeger |
| Vulnerable: |
Redhat Enterprise Linux 5.4 beta Redhat Enterprise Linux 5 Server Linux kernel 2.6.31 -rc3 Linux kernel 2.6.30 .1 Linux kernel 2.6.30 -rc6 Linux kernel 2.6.30 -rc5 Linux kernel 2.6.30 -rc3 Linux kernel 2.6.30 -rc2 Linux kernel 2.6.30 -rc1 Linux kernel 2.6.30 |
| Not Vulnerable: | |
Discussion
Linux Kernel 'tun_chr_pool()' NULL Pointer Dereference Vulnerability
The Linux kernel is prone to a local NULL-pointer dereference vulnerability.
A local attacker can exploit this issue to execute arbitrary code with superuser privileges or crash an affected kernel, denying service to legitimate users.
This issue was introduced in Linux kernel 2.6.30.
The Linux kernel is prone to a local NULL-pointer dereference vulnerability.
A local attacker can exploit this issue to execute arbitrary code with superuser privileges or crash an affected kernel, denying service to legitimate users.
This issue was introduced in Linux kernel 2.6.30.
Exploit / POC
Linux Kernel 'tun_chr_pool()' NULL Pointer Dereference Vulnerability
The following exploits are available:
The following exploits are available:
Solution / Fix
Linux Kernel 'tun_chr_pool()' NULL Pointer Dereference Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Linux Kernel 'tun_chr_pool()' NULL Pointer Dereference Vulnerability
References:
References:
- A brief note on the 2.6.30 kernel null pointer vulnerability (James Morris)
- Linux kernel Homepage (kernel.org)
- Oops in tun: bisected to Limit amount of queued packets per device (Christian Borntraeger)
- Re: PROBLEM: tun/tap crashes if open() /dev/net/tun and then poll() it. (Mariusz Kozlowski)