Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 230581 (CVE-2008-2372)

Summary: Linux <2.6.25.9 get_user_pages() ZERO_PAGE DoS (CVE-2008-2372)
Product: Gentoo Security Reporter: Robert Buchholz (RETIRED) <rbu>
Component: KernelAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: kernel, kfm
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=89f5b7da2a6bad2e84670422ab8192382a5aeb9f
Whiteboard: [linux <2.6.25.9]
Package list:
Runtime testing required: ---

Description Robert Buchholz (RETIRED) gentoo-dev 2008-07-02 23:29:50 UTC
CVE-2008-2372 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2372):
  The Linux kernel 2.6.24 and 2.6.25 before 2.6.25.9 allows local users to
  cause a denial of service (memory consumption) via a large number of calls to
  the get_user_pages function, which lacks a ZERO_PAGE optimization and results
  in allocation of "useless newly zeroed pages."
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2008-07-02 23:32:55 UTC
See also: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-2372
Comment 2 kfm 2008-10-13 17:01:45 UTC
Note: >=genpatches-2.6.25-7 is unaffected. Removing hardened as there are no vulnerable versions of hardened-sources in portage.