<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>116486</bug_id>
          
          <creation_ts>2005-12-23 05:42 0000</creation_ts>
          <short_desc>Kernel: various Local DoS (CVE-2005-{3808,3848,3857,3858})</short_desc>
          <delta_ts>2009-05-03 15:56:44 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Kernel</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>[linux &lt; 2.6.14.4]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>koon@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>gimli@gentoo.org</cc>
    
    <cc>kang@gentoo.org</cc>
    
    <cc>kerframil@gmail.com</cc>
    
    <cc>kern-sec@gentoo.org</cc>
    
    <cc>kumba@gentoo.org</cc>
    
    <cc>marineam@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-12-23 05:42:04 0000</bug_when>
            <thetext>From Ubuntu&apos;s USN-231-1

An integer overflow was discovered in the
invalidate_inode_pages2_range() function. By issuing 64-bit mmap calls
on a 32 bit system, a local user could exploit this to crash the
machine, thereby causing Denial of Service. This flaw does not affect
the amd64 platform, and does only affect Ubuntu 5.10. (CVE-2005-3808)

Ollie Wild discovered a memory leak in the icmp_push_reply() function.
By sending a large amount of specially crafted packets, a remote
attacker could exploit this to drain all memory, which eventually
leads to a Denial of Service. (CVE-2005-3848)

Chris Wrigth found a Denial of Service vulnerability in the
time_out_leases() function. By allocating a large number of VFS file
lock leases and having them timeout at the same time, a large number
of &apos;printk&apos; debugging statements was generated at the same time, which
could exhaust kernel memory. (CVE-2005-3857)

Patrick McHardy discovered a memory leak in the ip6_input_finish()
function. A remote attacker could exploit this by sending specially
crafted IPv6 packets, which would eventually drain all available
kernel memory, thus causing a Denial of Service. (CVE-2005-3858)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>plasmaroo@gentoo.org</who>
            <bug_when>2005-12-23 17:24:44 0000</bug_when>
            <thetext>Patches:

invalidate_inode_pages2_range issue: http://www.kernel.org/hg/linux-2.6/?cs=6d5ffbb49406

icmp_push_reply issue: http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=cb94c62c252796f42bb83fe40960d12f3ea5a82a;hp=22783649568a28839c5a362f47da7819ecfcbb9f

time_out_leases: http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=7ed0175a462c4c30f6df6fac1cccac058f997739

CVE-2005-3858 affects &lt; 2.6.13; patch:
http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=112508479120081&amp;w=2</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>plasmaroo@gentoo.org</who>
            <bug_when>2006-01-02 16:11:42 0000</bug_when>
            <thetext>invalidate_inode_pages2_range issue: 2.6.14.4
icmp_push_reply issue: 2.6.14
time_out_leases: 2.6.14.3
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>plasmaroo@gentoo.org</who>
            <bug_when>2006-01-02 16:23:08 0000</bug_when>
            <thetext>Adding maintainers:

ck-sources: marineam
hppa-sources: GMSoft
mips-sources-2.6.13: Kumba
rsbac-sources: kang
sh-sources: sh herd
xbox-sources: gimli</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2006-01-02 16:25:12 0000</bug_when>
            <thetext>feel free to update sh-sources as you wish ... just grab me if the mega sh patch stops applying after you do</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>marineam@gentoo.org</who>
            <bug_when>2006-01-05 12:09:19 0000</bug_when>
            <thetext>ck-sources already includes 2.6.14.5</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gmsoft@gentoo.org</who>
            <bug_when>2006-01-07 03:11:02 0000</bug_when>
            <thetext>Fixed on hppa in hppa-sources-2.6.15_p1.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>plasmaroo@gentoo.org</who>
            <bug_when>2006-01-15 06:40:44 0000</bug_when>
            <thetext>*** Bug 114230 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>plasmaroo@gentoo.org</who>
            <bug_when>2006-04-15 12:02:58 0000</bug_when>
            <thetext>All fixed now, resolving bug.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>