SB2006080501 - Improper access control in Linux kernel
Published: August 5, 2006
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper access control (CVE-ID: CVE-2006-3634)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The (1) __futex_atomic_op and (2) futex_atomic_cmpxchg_inatomic functions in Linux kernel 2.6.17-rc4 to 2.6.18-rc2 perform the atomic futex operation in the kernel address space instead of the user address space, which allows local users to cause a denial of service (crash).
Remediation
Install update from vendor's website.