PT-2005-3507 · Linux · Linux Kernel

Published

2005-08-17

·

Updated

2008-09-05

·

CVE-2005-2617

CVSS v2.0

3.6

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel versions 2.6.12 and later
Description The issue is related to the syscall32 setup pages function in syscall32.c, which does not properly check the return value of the insert vm struct function on 64-bit x86 platforms. This allows local users to cause a memory leak by using a 32-bit application with specially crafted ELF headers.
Recommendations For Linux kernel versions 2.6.12 and later, consider applying a patch that properly checks the return value of the insert vm struct function to prevent memory leaks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2617

Affected Products

Linux Kernel