---------------------------------------------------------------------- Secunia integrated with Microsoft WSUS http://secunia.com/blog/71/ ---------------------------------------------------------------------- TITLE: Linux Kernel 64bit Personality Handling Denial of Service SECUNIA ADVISORY ID: SA38354 VERIFY ADVISORY: http://secunia.com/advisories/38354/ DESCRIPTION: A vulnerability has been reported in the Linux Kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service). The vulnerability is caused due to an error when setting the personality of a process, which can be exploited to cause a kernel crash by e.g. executing a 64bit application with a missing ELF interpreter out of a 32bit application and causing a segmentation fault. Successful exploitation requires a 64bit system and may also require that core dumps are enabled. SOLUTION: Fixed in version 2.6.33-rc6. PROVIDED AND/OR DISCOVERED BY: Mathias Krause ORIGINAL ADVISORY: Mathias Krause: http://marc.info/?l=linux-mm&m=126466407724382&w=4 GIT commits: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=221af7f87b97431e3ee21ce4b0e77d5411cf1549 http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=05d43ed8a89c159ff641d472f970e3f1baa66318 http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=94673e968cbcce07fa78dac4b0ae05d24b5816e1 ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------