LWN.net Logo

kernel: multiple vulnerabilities

Package(s):linux-2.6.24 CVE #(s):CVE-2009-1192 CVE-2009-1242 CVE-2009-1265 CVE-2009-1337 CVE-2009-1338 CVE-2009-1439
Created:May 4, 2009 Updated:November 16, 2009
Description:

From the Debian advisory:

CVE-2009-1192: Shaohua Li reported an issue in the AGP subsystem they may allow local users to read sensitive kernel memory due to a leak of uninitialized memory.

CVE-2009-1242: Benjamin Gilbert reported a local denial of service vulnerability in the KVM VMX implementation that allows local users to trigger an oops.

CVE-2009-1265: Thomas Pollet reported an overflow in the af_rose implementation that allows remote attackers to retrieve uninitialized kernel memory that may contain sensitive data.

CVE-2009-1337: Oleg Nesterov discovered an issue in the exit_notify function that allows local users to send an arbitrary signal to a process by running a program that modifies the exit_signal field and then uses an exec system call to launch a setuid application.

CVE-2009-1338: Daniel Hokka Zakrisson discovered that a kill(-1) is permitted to reach processes outside of the current process namespace.

CVE-2009-1439: Pavan Naregundi reported an issue in the CIFS filesystem code that allows remote users to overwrite memory via a long nativeFileSystem field in a Tree Connect response during mount.

Alerts:
SuSE SUSE-SA:2009:055 2009-11-12
Red Hat RHSA-2009:1211-01 2009-08-13
SuSE SUSE-SA:2009:056 2009-11-16
SuSE SUSE-SA:2009:054 2009-11-11
Ubuntu USN-793-1 2009-07-02
Red Hat RHSA-2009:1132-01 2009-06-30
CentOS CESA-2009:1106 2009-06-19
Mandriva MDVSA-2009:135 2009-06-17
Red Hat RHSA-2009:1106-01 2009-06-16
CentOS CESA-2009:1550 2009-11-04
Red Hat RHSA-2009:1550-01 2009-11-03
SuSE SUSE-SA:2009:033 2009-06-16
SuSE SUSE-SA:2009:032 2009-06-09
SuSE SUSE-SA:2009:031 2009-06-09
SuSE SUSE-SA:2009:030 2009-06-08
Red Hat RHSA-2009:1081-01 2009-06-03
Red Hat RHSA-2009:1077-01 2009-06-02
Fedora FEDORA-2009-5383 2009-05-25
Fedora FEDORA-2009-5356 2009-05-25
SuSE SUSE-SA:2009:028 2009-05-20
Mandriva MDVSA-2009:119 2009-05-19
Debian DSA-1800-1 2009-05-15
Red Hat RHSA-2009:1024-01 2009-05-18
rPath rPSA-2009-0084-1 2009-05-15
CentOS CESA-2009:0473 2009-05-07
Red Hat RHSA-2009:0473-01 2009-05-07
Debian DSA-1794-1 2009-05-06
Debian DSA-1787-1 2009-05-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds