Back

HIGH

kernel: SELinux and mmap_min_addr

Published Aug 28, 2009

Description

The Linux kernel before 2.6.31-rc7 does not properly prevent mmap operations that target page zero and other low memory addresses, which allows local users to gain privileges by exploiting NULL pointer dereference vulnerabilities, related to (1) the default configuration of the allow_unconfined_mmap_low boolean in SELinux on Red Hat Enterprise Linux (RHEL) 5, (2) an error that causes allow_unconfined_mmap_low to be ignored in the unconfined_t domain, (3) lack of a requirement for the CAP_SYS_RAWIO capability for these mmap operations, and (4) interaction between the mmap_min_addr protection mechanism and certain application programs.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (40)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 28, 2009
Updated Aug 7, 2024
Reserved Aug 5, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Jul 31, 2009