PT-2009-1235 · Linux+1 · Linux Kernel+1

Bryn M. Reeves

+2

·

Published

2009-01-13

·

Updated

2023-02-13

·

CVE-2008-4307

CVSS v2.0

4.0

Medium

VectorAV:L/AC:H/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.6.26
Description A race condition exists in the do setlk function, allowing local users to cause a denial of service by interrupting an RPC call, resulting in a stray FL POSIX lock. This issue is related to the improper handling of a race between fcntl and close in the EINTR case.
Recommendations For Linux kernel versions prior to 2.6.26, update to version 2.6.26 or later to resolve the issue.

Fix

DoS

Race Condition

Weakness Enumeration

Related Identifiers

CVE-2008-4307
DSA-1787-1
DSA-1794-1
RHSA-2009:0451
RHSA-2009:0459
RHSA-2009:0473
RHSA-2009_0459
RHSA-2009_0473

Affected Products

Linux Kernel
Red Hat