kernel: splice local denial of service
Published Jun 6, 2009
4.7
MEDIUMCVSS 3.1
EPSS 0.59%
Description
The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of file creation and removal) via a series of splice system calls that trigger a deadlock between the generic_file_splice_write, splice_from_pipe, and ocfs2_file_splice_write functions.
Affected products
No data.
Configuration 1
- ≤ 2.6.19
- ≥ 2.6.27 · < 2.6.27.24
- ≥ 2.6.29 · < 2.6.29.4
- 2.6.30
- 2.6.30
Configuration 2
- 4.0
Configuration 3
- 6.06
- 8.04
- 8.10
- 9.04
Configuration 4
- 10.3
- 11.1
- 11.0
- 11
- 11
No data.
MRG for RHEL-5
kernel-rt-0:2.6.24.7-126.el5rt
Fixed · RHSA-2009:1157
| Product | Package | State | Advisory |
|---|---|---|---|
| MRG for RHEL-5 | kernel-rt-0:2.6.24.7-126.el5rt | Fixed | RHSA-2009:1157 |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect versions of Linux kernel as shipped with Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise Linux MRG 2. This issue was fixed in Red Hat Enterprise Linux MRG 1 via https://rhn.redhat.com/errata/RHSA-2009-1157.html.
References (24)
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=7bfac9ecf0585962fe13584f5cf526d8c8e76f17 x_refsource_CONFIRMBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html vendor-advisoryx_refsource_SUSEMailing List
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html vendor-advisoryx_refsource_SUSEMailing List
- http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00004.html vendor-advisoryx_refsource_SUSEMailing List
- http://secunia.com/advisories/35390 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/35394 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/35656 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/35847 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/36051 third-party-advisoryx_refsource_SECUNIABroken Link
- http://securitytracker.com/id?1022307 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://www.debian.org/security/2009/dsa-1844 vendor-advisoryx_refsource_DEBIANMailing ListPatch
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:135 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:148 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.openwall.com/lists/oss-security/2009/05/29/2 mailing-listx_refsource_MLISTMailing ListPatch
- http://www.openwall.com/lists/oss-security/2009/05/30/1 mailing-listx_refsource_MLISTExploitMailing ListPatch
- http://www.openwall.com/lists/oss-security/2009/06/02/2 mailing-listx_refsource_MLISTExploitMailing List
- http://www.openwall.com/lists/oss-security/2009/06/03/1 mailing-listx_refsource_MLISTExploitMailing List
- http://www.redhat.com/support/errata/RHSA-2009-1157.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.securityfocus.com/bid/35143 vdb-entryx_refsource_BIDBroken LinkExploitThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/usn-793-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2009-1961 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=503474 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2009-1961
- https://www.cve.org/CVERecord?id=CVE-2009-1961
Change history (0)
No recorded changes yet.