Vulnerability identifier: #VU94172
Vulnerability risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-20
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Linux kernel
Operating systems & Components /
Operating system
Vendor: Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The __scm_destroy function in net/core/scm.c in the Linux kernel 2.6.27.4, 2.6.26, and earlier makes indirect recursive calls to itself through calls to the fput function, which allows local users to cause a denial of service (panic) via vectors related to sending an SCM_RIGHTS message through a UNIX domain socket and closing file descriptors.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Linux kernel: All versions
External links
https://archives.neohapsis.com/archives/bugtraq/2009-01/0006.html
https://darkircop.org/unix.c
https://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.36.9
https://lists.opensuse.org/opensuse-security-announce/2008-12/msg00001.html
https://lists.opensuse.org/opensuse-security-announce/2009-01/msg00006.html
https://lists.opensuse.org/opensuse-security-announce/2009-01/msg00010.html
https://marc.info/?l=linux-netdev&m=122593044330973&w=2
https://secunia.com/advisories/32918
https://secunia.com/advisories/32998
https://secunia.com/advisories/33180
https://secunia.com/advisories/33556
https://secunia.com/advisories/33586
https://secunia.com/advisories/33623
https://secunia.com/advisories/33641
https://secunia.com/advisories/33704
https://securityreason.com/securityalert/4573
https://www.debian.org/security/2008/dsa-1681
https://www.debian.org/security/2008/dsa-1687
https://www.mandriva.com/security/advisories?name=MDVSA-2008:234
https://www.openwall.com/lists/oss-security/2008/11/06/1
https://www.redhat.com/support/errata/RHSA-2009-0009.html
https://www.redhat.com/support/errata/RHSA-2009-0014.html
https://www.redhat.com/support/errata/RHSA-2009-0225.html
https://www.securityfocus.com/archive/1/499700/100/0/threaded
https://www.securityfocus.com/archive/1/499744/100/0/threaded
https://www.securityfocus.com/archive/1/512019/100/0/threaded
https://www.securityfocus.com/bid/32154
https://www.securityfocus.com/bid/33079
https://www.securitytracker.com/id?1021292
https://www.securitytracker.com/id?1021511
https://www.ubuntu.com/usn/usn-679-1
https://bugzilla.redhat.com/show_bug.cgi?id=470201
https://exchange.xforce.ibmcloud.com/vulnerabilities/46538
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11694
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9558
https://rhn.redhat.com/errata/RHSA-2009-1550.html
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.