PT-2008-6968 · Opensuse+2 · Opensuse+2

Eugene Teo

·

Published

1970-01-01

·

Updated

2017-08-08

·

CVE-2008-4410

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions openSUSE kernel-rt debug (affected versions not specified) openSUSE kernel-rt (affected versions not specified) Linux kernel version 2.6.26.5
Description The issue involves multiple vulnerabilities in the kernel-rt and kernel-rt debug packages of the openSUSE operating system, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. Additionally, a specific vulnerability in the Linux kernel version 2.6.26.5 allows local users to cause a denial of service via crafted function calls, related to improper LDT selector state in the Java Runtime Environment.
Recommendations For openSUSE kernel-rt debug, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For openSUSE kernel-rt, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Linux kernel version 2.6.26.5, consider restricting access to the vmi write ldt entry function in arch/x86/kernel/vmi 32.c to minimize the risk of exploitation.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-05034
BDU:2015-05035
CVE-2008-4410

Affected Products

Java Runtime Environment
Linux Kernel
Opensuse