LWN.net Logo

kernel: denial of service

Package(s):kernel CVE #(s):CVE-2008-3528
Created:October 21, 2008 Updated:June 25, 2009
Description: From the CVE entry: The error-reporting functionality in (1) fs/ext2/dir.c, (2) fs/ext3/dir.c, and possibly (3) fs/ext4/dir.c in the Linux kernel 2.6.26.5 does not limit the number of printk console messages that report directory corruption, which allows physically proximate attackers to cause a denial of service (temporary system hang) by mounting a filesystem that has corrupted dir->i_size and dir->i_blocks values and performing (a) read or (b) write operations. NOTE: there are limited scenarios in which this crosses privilege boundaries.
Alerts:
Fedora FEDORA-2009-6846 2009-06-23
Fedora FEDORA-2009-5383 2009-05-25
CentOS CESA-2009:0326 2009-04-01
Red Hat RHSA-2009:0326-01 2009-04-01
Debian DSA-1687-1 2008-12-15
Debian DSA-1681-1 2008-12-04
SuSE SUSE-SA:2008:057 2008-12-04
SuSE SUSE-SA:2008:056 2008-12-03
CentOS CESA-2008:0972 2008-11-20
Red Hat RHSA-2008:0972-01 2008-11-19
SuSE SUSE-SR:2008:025 2008-11-14
rPath rPSA-2008-0316-1 2008-11-12
Mandriva MDVSA-2008:224-1 2008-11-07
Ubuntu USN-662-1 2008-11-05
Mandriva MDVSA-2008:224 2008-11-04
SuSE SUSE-SA:2008:053 2008-10-27
SuSE SUSE-SA:2008:052 2008-10-21
SuSE SUSE-SA:2008:051 2008-10-21
Red Hat RHSA-2009:0009-02 2009-01-22

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds