SB2008120906 - Resource management errors in Linux kernel



SB2008120906 - Resource management errors in Linux kernel

Published: December 9, 2008 Updated: June 20, 2024

Security Bulletin ID SB2008120906
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Resource management errors (CVE-ID: CVE-2008-5079)

The vulnerability allows a local user to perform a denial of service (DoS) attack.

net/atm/svc.c in the ATM subsystem in the Linux kernel 2.6.27.8 and earlier allows local users to cause a denial of service (kernel infinite loop) by making 2 calls to svc_listen for the same socket, and then reading a /proc/net/atm/*vc file, related to corruption of the vcc table.


Remediation

Install update from vendor's website.