PT-2006-6702 · Linux · Linux Kernel
Published
2006-11-22
·
Updated
2017-07-20
·
CVE-2006-6057
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 2.6.x up to 2.6.18
Description
The issue allows local users to cause a denial of service, resulting in a system crash, by utilizing a malformed gfs2 file stream. This triggers a NULL pointer dereference in the
init journal function.Recommendations
For Linux kernel versions 2.6.x up to 2.6.18, consider applying configuration changes to restrict access to the gfs2 file system until a fix is available. As a temporary workaround, avoid using the gfs2 file system to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel