PT-2009-3904 · Linux+1 · Linux Kernel+1

Eugene Teo

·

Published

2009-07-05

·

Updated

2024-02-15

·

CVE-2009-1388

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel version 2.6.18
Description The issue arises from the ptrace start function in kernel/ptrace.c, which does not properly handle simultaneous execution of the do coredump function. This allows local users to cause a denial of service (deadlock) via vectors involving the ptrace system call and a coredumping thread.
Recommendations For Linux kernel version 2.6.18, consider disabling the ptrace system call as a temporary workaround until a patch is available. Restrict access to the coredumping thread to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Improper Locking

Weakness Enumeration

Related Identifiers

CVE-2009-1388
RHSA-2009:1193
RHSA-2009_1193

Affected Products

Linux Kernel
Red Hat