Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Debian 6.0 moderate: DSA-2303-2 High Risk Patch for Linux-2.6

debian
Calendar Grey September 11, 2011
Debian Logo
Updated linux-2.6 packages rectify an issue concerning improper access to /proc/<pid>/status according to information provided by the Debian security team.
The linux-2.6 and user-mode-linux upgrades from DSA-2303-1 has caused a regression that can result in an oops during invalid accesses to /proc//maps files

Summary

The linux-2.6 and user-mode-linux upgrades from DSA-2303-1 has caused a
regression that can result in an oops during invalid accesses to
/proc//maps files.


The text of the original advisory is reproduced for reference:

Several vulnerabilities have been discovered in the Linux kernel that may lead
to a denial of service or privilege escalation. The Common Vulnerabilities and
Exposures project identifies the following problems:

CVE-2011-1020

Kees Cook discovered an issue in the /proc filesystem that allows local
users to gain access to sensitive process information after execution of a
setuid binary.

CVE-2011-1576

Ryan Sweat discovered an issue in the VLAN implementation. Local users may
be able to cause a kernel memory leak, resulting in a denial of service.

CVE-2011-2484

Vasiliy Kulikov of Openwall discovered that the number of exit handlers that
a process can register is not capped, resulting in local denial of service
through resource exhaustion (cpu time and mem...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: linux-2.6

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here