LOW
VM/Security: add security hook to do_brk
Published Dec 18, 2007
2.1
LOWCVSS 2.0
EPSS 0.44%
Description
Linux kernel 2.6.23 allows local users to create low pages in virtual userspace memory and bypass mmap_min_addr protection via a crafted executable file that calls the do_brk function.
Affected products
No data.
- 2.6.23
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 3, 4, 5 or Red Hat Enterprise MRG.
Weaknesses (1)
References (9)
- http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.24-rc5 x_refsource_CONFIRMExploit
- http://osvdb.org/40907 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/28070 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.securityfocus.com/bid/26831 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2007/4200 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2007-6434 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=426365 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2007-6434
- https://www.cve.org/CVERecord?id=CVE-2007-6434
| Link | Providers | Tags |
|---|---|---|
| http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.24-rc5 | x_refsource_CONFIRMExploit | |
| http://osvdb.org/40907 | vdb-entryx_refsource_OSVDB | |
| http://secunia.com/advisories/28070 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.securityfocus.com/bid/26831 | vdb-entryx_refsource_BID | |
| http://www.vupen.com/english/advisories/2007/4200 | vdb-entryx_refsource_VUPEN | |
| https://access.redhat.com/security/cve/CVE-2007-6434 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=426365 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2007-6434 | ||
| https://www.cve.org/CVERecord?id=CVE-2007-6434 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 18, 2007
Updated Aug 7, 2024
Reserved Dec 18, 2007
Link CVE-2007-6434
CISA Vulnrichment
Updated n/a