PT-2006-3552 · Linux · Linux Kernel

Tony Griffiths

·

Published

2006-05-27

·

Updated

2017-07-20

·

CVE-2006-2629

CVSS v2.0

4.0

Medium

VectorAV:L/AC:H/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions 2.6.15 through 2.6.17
Description A race condition issue exists that allows local users to cause a denial of service by creating and exiting a large number of tasks and then accessing the /proc entry of a task that is exiting. This leads to memory corruption, resulting in a failure in the prune dcache function or a BUG ON error in include/linux/list.h.
Recommendations For Linux kernel versions 2.6.15 through 2.6.17, consider applying a patch to fix the race condition issue, or as a temporary workaround, restrict the creation of tasks to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2629

Affected Products

Linux Kernel