LWN.net Logo

Advertisement

Connecting kernel, userspace, and graphics - the plumbing of Linux

Advertise here

Package(s):kernel CVE #(s):CVE-2008-2136 CVE-2008-2148
Created:May 15, 2008 Updated:July 23, 2008
Description: The kernel has several denial of service vulnerabilities. From the secunia report:

1) An error exists in the implementation of the "sys_utimensat()" system call. This can be exploited to update the access or modification time of arbitrary files via specially crafted arguments passed to the affected system call.

2) A memory leak exists in the "ipip6_rcv()" function included in the IPv6 over IPv4 (SIP) tunneling driver. This can be exploited to potentially exhaust all available memory via specially crafted network packets.

Alerts:
rPath rPSA-2008-0169-1 2008-05-14
Debian DSA-1588-1 2008-05-27
Debian DSA-1588-2 2008-05-30
SuSE SUSE-SA:2008:030 2008-06-20
SuSE SUSE-SA:2008:032 2008-07-07
Ubuntu USN-625-1 2008-07-15
Red Hat RHSA-2008:0607-01 2008-07-23

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.