LWN.net Logo

kernel: arbitrary code execution, DoS

Package(s):kernel CVE #(s):CAN-2005-0867 CAN-2005-0937
Created:April 11, 2005 Updated:April 19, 2005
Description: Alexander Nyberg discovered an integer overflow in the sysfs_write_file() function. A local attacker could exploit this to crash the kernel or possibly even execute arbitrary code with root privileges by writing to an user-writable file in /sys under certain low-memory conditions. However, there are very few cases where a user-writeable sysfs file actually exists. (CAN-2005-0867)

Olof Johansson discovered a Denial of Service vulnerability in the futex functions, which provide semaphores for exclusive locking of resources. A local attacker could possibly exploit this to cause a kernel deadlock. (CAN-2005-0937)

Alerts:
Red Hat RHSA-2005:366-01 2005-04-19
Ubuntu USN-110-1 2005-04-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds