PT-2008-6968 · Opensuse+2 · Opensuse+2
Eugene Teo
·
Published
1970-01-01
·
Updated
2017-08-08
·
CVE-2008-4410
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
openSUSE kernel-rt debug (affected versions not specified)
openSUSE kernel-rt (affected versions not specified)
Linux kernel version 2.6.26.5
Description
The issue involves multiple vulnerabilities in the kernel-rt and kernel-rt debug packages of the openSUSE operating system, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. Additionally, a specific vulnerability in the Linux kernel version 2.6.26.5 allows local users to cause a denial of service via crafted function calls, related to improper LDT selector state in the Java Runtime Environment.
Recommendations
For openSUSE kernel-rt debug, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For openSUSE kernel-rt, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Linux kernel version 2.6.26.5, consider restricting access to the
vmi write ldt entry function in arch/x86/kernel/vmi 32.c to minimize the risk of exploitation.RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Java Runtime Environment
Linux Kernel
Opensuse