Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 146386 - Kernel: SPARC local DoS with corrupted ELFs (CVE-2006-4538)
Summary: Kernel: SPARC local DoS with corrupted ELFs (CVE-2006-4538)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: High normal
Assignee: Gentoo Security
URL: http://www.kernel.org/git/?p=linux/ke...
Whiteboard: [linux <2.6.17.11]
Keywords:
Depends on:
Blocks:
 
Reported: 2006-09-05 06:15 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2009-07-10 22:58 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-09-05 06:15:46 UTC
IA64: local DoS with corrupted ELFs
 
 This patch prevents cross-region mappings
 on IA64 and SPARC which could lead to system crash.
 
 davem@ confirmed: "This looks fine to me." :)
Comment 1 Harlan Lieberman-Berg (RETIRED) gentoo-dev 2006-10-27 12:58:16 UTC
No patch is attached; not enough information is given about the vulnerability. Please reopen with additional information.
Comment 2 Tim Yamin (RETIRED) gentoo-dev 2006-10-28 05:37:04 UTC
Umm, there is a patch. Look at the URL of this bug.
Comment 3 Tim Yamin (RETIRED) gentoo-dev 2006-10-28 05:53:42 UTC
IA64 is fine, has 2.6.18 stabled. SPARC has gentoo-sources 2.6.17-r8 stabled which is fine, this is fixed usptream in 2.6.17.11. hardened-sources-2.6.17-r1 has genpatches r8 which also fixes this.
Comment 4 Bjoern Tropf (RETIRED) gentoo-dev 2009-07-10 22:58:17 UTC
CVE-2006-4538:
Linux kernel 2.6.17 and earlier, when running on IA64 or SPARC platforms, allows local users to cause a denial of service (crash) via a malformed ELF file that triggers memory maps that cross region boundaries.