PT-2008-3849 · Red Hat+1 · Enterprise Linux+13

Alexei Dobryanov

+1

·

Publicado

2008-06-25

·

Atualizado

2023-02-13

·

CVE-2008-2365

CVSS v2.0

4.7

Média

VetorAV:L/AC:M/Au:N/C:N/I:N/A:C
Race condition in the ptrace and utrace support in the Linux kernel 2.6.9 through 2.6.25, as used in Red Hat Enterprise Linux (RHEL) 4, allows local users to cause a denial of service (oops) via a long series of PTRACE ATTACH ptrace calls to another user's process that trigger a conflict between utrace detach and report quiescent, related to "late ptrace may attach() check" and "race around &dead engine ops setting," a different vulnerability than CVE-2007-0771 and CVE-2008-1514. NOTE: this issue might only affect kernel versions before 2.6.16.x.

Exploit

Correção

DoS

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-2365
RHSA-2008:0508
RHSA-2008_0508

Produtos afetados

Enterprise Linux
Suse Linux Enterprise Desktop
Kernel
Kernel-Devel
Kernel-Doc
Kernel-Hugemem
Kernel-Hugemem-Devel
Kernel-Largesmp
Kernel-Largesmp-Devel
Kernel-Smp
Kernel-Smp-Devel
Xnu Kernel
Kernel-Xen-Devel
Linux Kernel