PT-2007-6895 · Linux+1 · Linux Kernel+1

Warren Togami

·

Published

2007-12-20

·

Updated

2023-02-13

·

CVE-2007-5966

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.6.23.10
Description The issue is related to an integer overflow in the hrtimer start function, which can be exploited by local users to execute arbitrary code or cause a denial of service, resulting in a system panic. This can be achieved by providing a large relative timeout value.
Recommendations For Linux kernel versions prior to 2.6.23.10, update to version 2.6.23.10 or later to resolve the issue.

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2007-5966
DSA-1436-1
RHSA-2008:0585
RHSA-2009:1193
RHSA-2009_1193
RHSA-2010:0079

Affected Products

Linux Kernel
Red Hat