SB2006041801 - Input validation error in Xen



SB2006041801 - Input validation error in Xen

Published: April 18, 2006 Updated: July 28, 2020

Security Bulletin ID SB2006041801
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Input validation error (CVE-ID: CVE-2006-0744)

The vulnerability allows a local non-authenticated attacker to perform a denial of service (DoS) attack.

Linux kernel before 2.6.16.5 does not properly handle uncanonical return addresses on Intel EM64T CPUs, which reports an exception in the SYSRET instead of the next instruction, which causes the kernel exception handler to run on the user stack with the wrong GS.


Remediation

Install update from vendor's website.

References