MEDIUM
kernel: do_coredump() vs ptrace_start() deadlock
Published Jul 5, 2009
5.5
MEDIUMCVSS 3.1
EPSS 0.36%
Description
The ptrace_start function in kernel/ptrace.c in the Linux kernel 2.6.18 does not properly handle simultaneous execution of the do_coredump function, which allows local users to cause a denial of service (deadlock) via vectors involving the ptrace system call and a coredumping thread.
Affected products
No data.
- 2.6.18
No data.
Red Hat Enterprise Linux 5
kernel-0:2.6.18-128.4.1.el5
Fixed · RHSA-2009:1193
Red Hat Enterprise Linux 5.3.Z - Server Only
kernel-0:2.6.18-128.4.1.el5
Fixed · RHSA-2009:1193
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel-0:2.6.18-128.4.1.el5 | Fixed | RHSA-2009:1193 |
| Red Hat Enterprise Linux 5.3.Z - Server Only | kernel-0:2.6.18-128.4.1.el5 | Fixed | RHSA-2009:1193 |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, and Red Hat Enterprise MRG.
Weaknesses (1)
References (17)
- http://marc.info/?l=oss-security&m=124654277229434&w=2 mailing-listx_refsource_MLISTMailing ListPatch
- http://osvdb.org/55679 vdb-entryx_refsource_OSVDBBroken Link
- http://secunia.com/advisories/36131 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/37471 third-party-advisoryx_refsource_SECUNIABroken Link
- http://www.redhat.com/support/errata/RHSA-2009-1193.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.securityfocus.com/archive/1/507985/100/0/threaded mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/35559 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.vmware.com/security/advisories/VMSA-2009-0016.html x_refsource_CONFIRMThird Party Advisory
- http://www.vupen.com/english/advisories/2009/3316 vdb-entryx_refsource_VUPENBroken Link
- https://access.redhat.com/security/cve/CVE-2009-1388 Vendor Advisory
- https://bugzilla.redhat.com/attachment.cgi?id=346615 x_refsource_CONFIRMMailing ListPatch
- https://bugzilla.redhat.com/attachment.cgi?id=346742 x_refsource_CONFIRMPatch
- https://bugzilla.redhat.com/show_bug.cgi?id=504263 x_refsource_CONFIRMIssue TrackingPatch
- https://nvd.nist.gov/vuln/detail/CVE-2009-1388
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8625 vdb-entrysignaturex_refsource_OVALBroken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8680 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cve.org/CVERecord?id=CVE-2009-1388
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 5, 2009
Updated Aug 7, 2024
Reserved Apr 23, 2009
Link CVE-2009-1388
CISA Vulnrichment
Updated n/a