SB2007071202 - Resource exhaustion in Linux kernel
Published: July 12, 2007
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource exhaustion (CVE-ID: CVE-2007-3720)
The vulnerability allows a local user to perform service disruption.
The process scheduler in the Linux kernel 2.4 performs scheduling based on CPU billing gathered from periodic process sampling ticks, which allows local users to cause a denial of service (CPU consumption) by performing voluntary nanosecond sleeps that result in the process not being active during a clock interrupt, as described in 'Secretly Monopolizing the CPU Without Superuser Privileges.'
Remediation
Install update from vendor's website.