PT-2004-3693 · Linux · Linux Kernel
Chris Wright
·
Published
1970-01-01
·
Updated
2024-02-15
·
CVE-2005-3847
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 2.6.13
Linux kernel versions prior to 2.6.12.6
Description
The issue allows local users to cause a denial of service (deadlock) by sending a SIGKILL to a real-time threaded process while it is performing a core dump. This can lead to disruption of service and potential data loss. The
handle stop signal function in signal.c is vulnerable to this issue.Recommendations
For Linux kernel versions prior to 2.6.13, update to version 2.6.13 or later to resolve the issue.
For Linux kernel versions prior to 2.6.12.6, update to version 2.6.12.6 or later to resolve the issue.
As a temporary workaround, consider restricting access to real-time threaded processes to minimize the risk of exploitation.
Fix
Improper Locking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel