SB2008050804 - Race condition in Linux kernel



SB2008050804 - Race condition in Linux kernel

Published: May 8, 2008

Security Bulletin ID SB2008050804
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Race condition (CVE-ID: CVE-2008-1669)

The vulnerability allows a local user to execute arbitrary code.

Linux kernel before 2.6.25.2 does not apply a certain protection mechanism for fcntl functionality, which allows local users to (1) execute code in parallel or (2) exploit a race condition to obtain 're-ordered access to the descriptor table.'


Remediation

Install update from vendor's website.

References