Vulnerability identifier: #VU95774
Vulnerability risk: Low
CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-401
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Linux kernel
Operating systems & Components /
Operating system
Vendor: Linux Foundation
Description
The vulnerability allows a local user to perform service disruption.
The do_fork function in Linux 2.4.x before 2.4.26, and 2.6.x before 2.6.6, does not properly decrement the mm_count counter when an error occurs after the mm_struct for a child process has been activated, which triggers a memory leak that allows local users to cause a denial of service (memory exhaustion) via the clone (CLONE_VM) system call.
Mitigation
Install update from vendor's repository.
Vulnerable software versions
Linux kernel: All versions
External links
https:ftp://patches.sgi.com/support/free/security/advisories/20040504-01-U.asc
ftp://patches.sgi.com/support/free/security/advisories/20040505-01-U.asc
https://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000846
https://fedoranews.org/updates/FEDORA-2004-111.shtml
https://security.gentoo.org/glsa/glsa-200407-02.xml
https://www.novell.com/linux/security/advisories/2004_10_kernel.html
https://www.redhat.com/support/errata/RHSA-2004-255.html
https://www.redhat.com/support/errata/RHSA-2004-260.html
https://www.redhat.com/support/errata/RHSA-2004-327.html
https://www.turbolinux.com/security/2004/TLSA-2004-14.txt
https://www.ciac.org/ciac/bulletins/o-164.shtml
https://www.securityfocus.com/bid/10221
https://secunia.com/advisories/11429
https://secunia.com/advisories/11464
https://secunia.com/advisories/11486
https://secunia.com/advisories/11541
https://secunia.com/advisories/11861
https://secunia.com/advisories/11891
https://secunia.com/advisories/11892
https://www.debian.org/security/2006/dsa-1070
https://www.debian.org/security/2006/dsa-1067
https://www.debian.org/security/2006/dsa-1069
https://secunia.com/advisories/20162
https://secunia.com/advisories/20163
https://secunia.com/advisories/20202
https://www.debian.org/security/2006/dsa-1082
https://secunia.com/advisories/20338
https://www.mandriva.com/security/advisories?name=MDKSA-2004:037
https://marc.info/?l=linux-kernel&m=108139073506983&w=2
https://exchange.xforce.ibmcloud.com/vulnerabilities/16002
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2819
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10297
https://linux.bkbits.net:8080/linux-2.6/cset%40407b1217x4jtqEkpFW2g_-RcF0726A
https://linux.bkbits.net:8080/linux-2.4/cset%40407bf20eDeeejm8t36_tpvSE-8EFHA
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.