LWN.net Logo

kernel: denial of service

Package(s):kernel CVE #(s):CVE-2009-3288
Created:October 22, 2009 Updated:May 7, 2010
Description: From the National Vulnerability Database entry:

"The sg_build_indirect function in drivers/scsi/sg.c in Linux kernel 2.6.28-rc1 through 2.6.31-rc8 uses an incorrect variable when accessing an array, which allows local users to cause a denial of service (kernel OOPS and NULL pointer dereference), as demonstrated by using xcdroast to duplicate a CD. NOTE: this is only exploitable by users who can open the cdrom device."

Alerts:
rPath rPSA-2010-0037-1 2010-05-07
Ubuntu USN-852-1 2009-10-22

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds