SB2006071001 - Resource management errors in Linux kernel



SB2006071001 - Resource management errors in Linux kernel

Published: July 10, 2006

Security Bulletin ID SB2006071001
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Resource management errors (CVE-ID: CVE-2006-2936)

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

The ftdi_sio driver (usb/serial/ftdi_sio.c) in Linux kernel 2.6.x up to 2.6.17, and possibly later versions, allows local users to cause a denial of service (memory consumption) by writing more data to the serial port than the hardware can handle, which causes the data to be queued.


Remediation

Install update from vendor's website.

References