[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    Re: [oss-security] CVE request: kernel: clock_nanosleep() with
From:       "Steven M. Christey" <coley () linus ! mitre ! org>
Date:       2009-08-18 20:20:38
Message-ID: Pine.GSO.4.51.0908181620190.17763 () faron ! mitre ! org
[Download RAW message or body]


======================================================
Name: CVE-2009-2767
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2767
Reference: MLIST:[linux-kernel] 20090804 Re: [PATCH] posix-timers: fix oops in \
                clock_nanosleep() with CLOCK_MONOTONIC_RAW
Reference: URL:http://lkml.org/lkml/2009/8/4/28
Reference: MLIST:[linux-kernel] 20090804 Re: [PATCH] posix-timers: fix oops in \
                clock_nanosleep() with CLOCK_MONOTONIC_RAW
Reference: URL:http://lkml.org/lkml/2009/8/4/40
Reference: CONFIRM:http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=70d715fd0597f18528f389b5ac59102263067744
                
Reference: CONFIRM:http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.31-rc6
Reference: SECUNIA:36200
Reference: URL:http://secunia.com/advisories/36200
Reference: VUPEN:ADV-2009-2197
Reference: URL:http://www.vupen.com/english/advisories/2009/2197
Reference: XF:linux-kernel-clocknanosleep-priv-escalation(52317)
Reference: URL:http://xforce.iss.net/xforce/xfdb/52317

The init_posix_timers function in kernel/posix-timers.c in the Linux
kernel before 2.6.31-rc6 allows local users to cause a denial of
service (OOPS) or possibly gain privileges via a CLOCK_MONOTONIC_RAW
clock_nanosleep call that triggers a NULL pointer dereference.


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic