New User, Welcome!     Login

UNIX domain socket

[SECURITY] [DSA 1927-1] New Linux 2.6.26 packages fix several vulnerabilities

    dereference).

CVE-2009-3621

    Tomoki Sekiyama discovered a deadlock condition in the UNIX domain
    socket implementation. Local users can exploit this vulnerability
    to cause a denial of service (system hang).

CVE-2009-3638

    David Wagner reported an overflow in the KVM subsystem on i386

[SECURITY] [DSA 1928-1] New Linux 2.6.24 packages fix several vulnerabilities

    dereference).

CVE-2009-3621

    Tomoki Sekiyama discovered a deadlock condition in the UNIX domain
    socket implementation. Local users can exploit this vulnerability
    to cause a denial of service (system hang).

For the oldstable distribution (etch), this problem has been fixed in
version 2.6.24-6~etchnhalf.9etch1.


[SECURITY] [DSA 1929-1] New Linux 2.6.18 packages fix several vulnerabilities

    to sensitive kernel memory.

CVE-2009-3621

    Tomoki Sekiyama discovered a deadlock condition in the UNIX domain
    socket implementation. Local users can exploit this vulnerability
    to cause a denial of service (system hang).

For the oldstable distribution (etch), this problem has been fixed in
version 2.6.18.dfsg.1-26etch1.


[ MDVSA-2008:234 ] kernel

 
 The __scm_destroy function in net/core/scm.c in the Linux kernel
 2.6.27.4, 2.6.26, and earlier makes indirect recursive calls to
 itself through calls to the fput function, which allows local users
 to cause a denial of service (panic) via vectors related to sending
 an SCM_RIGHTS message through a UNIX domain socket and closing file
 descriptors. (CVE-2008-5029)
 
 Additionaly, support for a broadcom bluetooth dongle was added to btusb
 driver, an eeepc shutdown hang caused by snd-hda-intel was fixed,
 a Realtek auto-mute bug was fixed, the pcspkr driver was reenabled,



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!