Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 93666 - Kernel: Local DoS in fib_seq_start() (CAN-2005-1041)
Summary: Kernel: Local DoS in fib_seq_start() (CAN-2005-1041)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://cve.mitre.org/cgi-bin/cvename....
Whiteboard: [linux <2.6.11.5]
Keywords:
Depends on:
Blocks:
 
Reported: 2005-05-23 04:24 UTC by Thierry Carrez (RETIRED)
Modified: 2009-05-03 14:36 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thierry Carrez (RETIRED) gentoo-dev 2005-05-23 04:24:51 UTC
From Ubuntu's USN-131-1

A Denial of Service vulnerability was discovered in the
fib_seq_start() function(). This allowed a local user to crash the
system by reading /proc/net/route in a certain way. (CAN-2005-1041)
Comment 1 Micheal Marineau (RETIRED) gentoo-dev 2005-05-25 13:11:39 UTC
A little bit of info: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1041

The actual post with a patch:
http://marc.theaimsgroup.com/?l=bk-commits-head&m=111186506706769&w=2
Comment 2 Micheal Marineau (RETIRED) gentoo-dev 2005-05-25 13:22:45 UTC
This was actually committed a long while back. (note the date on the email is march)

Here's the bk commit: http://linux.bkbits.net:8080/linux-2.6/cset@1.1982.168.25

Given the commit date of 2005-03-18 it looks like 2.6.5 and up should be ok for
that issue. :-)

There may be some other CANs in that Ubuntu advisory that are for newer issues
though: https://www.ubuntulinux.org/support/documentation/usn/usn-131-1
Comment 3 Micheal Marineau (RETIRED) gentoo-dev 2005-05-25 13:26:08 UTC
Oh geezzz, I feel really stupid now. When I glanced at the release dates for the
kernels I looked at 2004, why I didn't realize that 2.6.5 was a year ago, and
not two moths ago, I have no idea, sorry for that bit of extra noise :-(
Comment 4 Tim Yamin (RETIRED) gentoo-dev 2005-06-11 05:30:50 UTC
Yep, patch you need is here:
http://linux.bkbits.net:8080/linux-2.6/cset@1.1982.168.25

I've just checked that USN and everything else already has bugs filed.
Comment 5 Tim Yamin (RETIRED) gentoo-dev 2005-06-11 05:32:24 UTC
This only affects < 2.6.11.
Comment 6 Tim Yamin (RETIRED) gentoo-dev 2005-07-07 14:55:57 UTC
Only affects < 2.6.11 and the only affected sources were mips-sources-2.6.10
which were patched a while ago. Closing bug as FIXED.