SB2006032701 - Resource management errors in Linux kernel
Published: March 27, 2006
Security Bulletin ID
SB2006032701
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management errors (CVE-ID: CVE-2006-1066)
The vulnerability allows a local user to perform service disruption.
Linux kernel 2.6.16-rc2 and earlier, when running on x86_64 systems with preemption enabled, allows local users to cause a denial of service (oops) via multiple ptrace tasks that perform single steps, which can cause corruption of the DEBUG_STACK stack during the do_debug function call.
Remediation
Install update from vendor's website.
References
- http://marc.info/?l=linux-kernel&m=113932292516359&w=2
- http://secunia.com/advisories/19374
- http://secunia.com/advisories/19955
- http://secunia.com/advisories/21614
- http://www.debian.org/security/2006/dsa-1017
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:151
- http://www.osvdb.org/24098
- http://www.securityfocus.com/bid/17216
- https://usn.ubuntu.com/281-1/