SB2005112506 - Improper locking in Linux kernel
Published: November 25, 2005
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2005-3805)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
A locking problem in POSIX timer cleanup handling on exit in Linux kernel 2.6.10 to 2.6.14, when running on SMP systems, allows local users to cause a denial of service (deadlock) involving process CPU timers.
Remediation
Install update from vendor's website.
References
- http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=25f407f0b668f5e4ebd5d13e1fb4306ba6427ead
- http://secunia.com/advisories/17917
- http://secunia.com/advisories/17918
- http://secunia.com/advisories/18203
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:018
- http://www.securityfocus.com/advisories/9806
- http://www.securityfocus.com/archive/1/419522/100/0/threaded
- http://www.securityfocus.com/archive/1/427981/100/0/threaded
- http://www.securityfocus.com/bid/15722
- https://usn.ubuntu.com/231-1/