SB2007071202 - Resource exhaustion in Linux kernel



SB2007071202 - Resource exhaustion in Linux kernel

Published: July 12, 2007

Security Bulletin ID SB2007071202
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Resource exhaustion (CVE-ID: CVE-2007-3720)

The vulnerability allows a local user to perform service disruption.

The process scheduler in the Linux kernel 2.4 performs scheduling based on CPU billing gathered from periodic process sampling ticks, which allows local users to cause a denial of service (CPU consumption) by performing voluntary nanosecond sleeps that result in the process not being active during a clock interrupt, as described in 'Secretly Monopolizing the CPU Without Superuser Privileges.'


Remediation

Install update from vendor's website.