|
|
Log in / Subscribe / Register

kernel 2.4 - two new vulnerabilities

Package(s):kernel CVE #(s):CAN-2003-0244 CAN-2003-0246
Created:May 14, 2003 Updated:July 25, 2003
Description: The 2.4.20 (and prior) kernel contains a couple of vulnerabilities that are worth fixing.
  • The ioperm() system call doesn't perform proper checking, allowing a local user to manipulate arbitrary I/O ports.

  • The networking code contains a remotely exploitable denial of service condition; see the May 24 Security Page for details.

Alerts:
Mandrake MDKSA-2003:066-2 kernel 2003-07-25
Conectiva CLA-2003:701 kernel 2003-07-22
Mandrake MDKSA-2003:066-1 kernel 2003-07-21
Mandrake MDKSA-2003:074 kernel 2003-07-15
Slackware SSA:2003-168-01 kernel 2003-06-17
Mandrake MDKSA-2003:066 kernel 2003-06-11
Debian DSA-312-1 kernel-patch-2.4.18-powerpc 2003-06-09
Debian DSA-311-1 kernel 2003-06-08
Red Hat RHSA-2003:187-01 kernel 2003-06-03
Red Hat RHSA-2003:145-01 kernel 2003-05-27
EnGarde ESA-20030515-017 kernel 2003-05-15
Red Hat RHSA-2003:172-00 kernel 2003-05-14

The LWN site is currently under high scraper load, so comment display has been suppressed for anonymous users. If you are a human, you may read the comments by clicking the button below:

Note: you can avoid this step in the future by logging into your LWN account.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds