PT-2019-6624 · Linux · Pax-Linux
Francisco Blas Izquierdo Riera
+1
·
Published
2019-12-26
·
Updated
2020-01-10
·
CVE-2011-1474
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
pax-linux versions 2.6.32.33-test79.patch, 2.6.37.4-test14.patch, 2.6.38-test3.patch
Description
A locally exploitable DOS issue was found in pax-linux. It is caused by a bad bounds check in
arch get unmapped area topdown triggered by programs doing an mmap after a MAP GROWSDOWN mmap, creating an infinite loop condition without releasing the VM semaphore, eventually leading to a system crash.Recommendations
For version 2.6.32.33-test79.patch, consider disabling the
arch get unmapped area topdown function to prevent the infinite loop condition.
For version 2.6.37.4-test14.patch, restrict the use of mmap with MAP GROWSDOWN to minimize the risk of exploitation.
For version 2.6.38-test3.patch, avoid using mmap after MAP GROWSDOWN mmap until the issue is resolved.Fix
Infinite Loop
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pax-Linux