kernel: AF_UNIX: Fix deadlock on connecting to shutdown socket
Published Oct 22, 2009
5.5
MEDIUMCVSS 3.1
EPSS 0.99%
Description
net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing a series of connect operations to this socket.
Affected products
No data.
Configuration 1
- ≤ 2.6.31.4
Configuration 2
- 6.06
- 8.04
- 8.10
- 9.04
- 9.10
Configuration 3
- 10
Configuration 4
- 11.0
- 11.2
- 10
- 10
- 10
- 10
No data.
MRG for RHEL-5
kernel-rt-0:2.6.24.7-137.el5rt
Fixed · RHSA-2009:1540
Red Hat Enterprise Linux 4
kernel-0:2.6.9-89.0.18.EL
Fixed · RHSA-2009:1671
Red Hat Enterprise Linux 5
kernel-0:2.6.18-164.9.1.el5
Fixed · RHSA-2009:1670
| Product | Package | State | Advisory |
|---|---|---|---|
| MRG for RHEL-5 | kernel-rt-0:2.6.24.7-137.el5rt | Fixed | RHSA-2009:1540 |
| Red Hat Enterprise Linux 4 | kernel-0:2.6.9-89.0.18.EL | Fixed | RHSA-2009:1671 |
| Red Hat Enterprise Linux 5 | kernel-0:2.6.18-164.9.1.el5 | Fixed | RHSA-2009:1670 |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue is not planned to be fixed in Red Hat Enterprise Linux 3, due to this product being in Production 3 of its maintenance life-cycle, where only qualified security errata of important or critical impact are addressed. For further information about Errata Support Policy, visit: https://access.redhat.com/support/policy/updates/errata/
References (30)
- http://git.kernel.org/?p=linux/kernel/git/davem/net-2.6.git%3Ba=commit%3Bh=77238f2b942b38ab4e7f3aced44084493e4a8675 x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00007.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.vmware.com/pipermail/security-announce/2010/000082.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://lkml.org/lkml/2009/10/19/50 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://patchwork.kernel.org/patch/54678/ x_refsource_CONFIRMExploitMailing ListThird Party Advisory
- http://secunia.com/advisories/37086 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/37909 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/38017 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/38794 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/38834 third-party-advisoryx_refsource_SECUNIABroken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:329 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.openwall.com/lists/oss-security/2009/10/19/2 mailing-listx_refsource_MLISTExploitMailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2009/10/19/4 mailing-listx_refsource_MLISTExploitMailing ListPatchThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2009-1670.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.redhat.com/support/errata/RHSA-2009-1671.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.ubuntu.com/usn/usn-864-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.vupen.com/english/advisories/2010/0528 vdb-entryx_refsource_VUPENBroken Link
- https://access.redhat.com/security/cve/CVE-2009-3621 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=529626 x_refsource_CONFIRMExploitIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-3602 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-3621
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6895 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9921 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2009-1540.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2009-3621
- https://www.redhat.com/archives/fedora-package-announce/2009-November/msg00190.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data