Oval Definition:oval:org.mitre.oval:def:8300
Revision Date:2014-06-23Version:19
Title:DSA-1800 linux-2.6 -- denial of service/privilege escalation/sensitive memory leak
Description:Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service, privilege escalation or a sensitive memory leak. The Common Vulnerabilities and Exposures project identifies the following problems: Chris Evans discovered a situation in which a child process can send an arbitrary signal to its parent. Roland McGrath discovered an issue on amd64 kernels that allows local users to circumvent system call audit configurations which filter based on the syscall numbers or argument details. Roland McGrath discovered an issue on amd64 kernels with CONFIG_SECCOMP enabled. By making a specially crafted syscall, local users can bypass access restrictions. Jiri Olsa discovered that a local user can cause a denial of service (system hang) using a SHM_INFO shmctl call on kernels compiled with CONFIG_SHMEM disabled. This issue does not affect prebuilt Debian kernels. Mikulas Patocka reported an issue in the console subsystem that allows a local user to cause memory corruption by selecting a small number of 3-byte UTF-8 characters. Igor Zhbanov reported that nfsd was not properly dropping CAP_MKNOD, allowing users to create device nodes on file systems exported with root_squash. Dan Carpenter reported a coding issue in the selinux subsystem that allows local users to bypass certain networking checks when running with compat_net=1. Shaohua Li reported an issue in the AGP subsystem they may allow local users to read sensitive kernel memory due to a leak of uninitialised memory. Benjamin Gilbert reported a local denial of service vulnerability in the KVM VMX implementation that allows local users to trigger an oops. Thomas Pollet reported an overflow in the af_rose implementation that allows remote attackers to retrieve uninitialised kernel memory that may contain sensitive data. Oleg Nesterov discovered an issue in the exit_notify function that allows local users to send an arbitrary signal to a process by running a program that modifies the exit_signal field and then uses an exec system call to launch a setuid application. Daniel Hokka Zakrisson discovered that a kill(-1) is permitted to reach processes outside of the current process namespace. Pavan Naregundi reported an issue in the CIFS filesystem code that allows remote users to overwrite memory via a long nativeFileSystem field in a Tree Connect response during mount.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2009-0028
CVE-2009-0834
CVE-2009-0835
CVE-2009-0859
CVE-2009-1046
CVE-2009-1072
CVE-2009-1184
CVE-2009-1192
CVE-2009-1242
CVE-2009-1265
CVE-2009-1337
CVE-2009-1338
CVE-2009-1439
DSA-1800
Platform(s):Debian GNU/Linux 5.0
Product(s):linux-2.6
Definition Synopsis
  • Debian GNU/Linux 5.0 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • linux-patch-debian-2.6.26 is earlier than 2.6.26-15lenny2
  • OR linux-support-2.6.26-2 is earlier than 2.6.26-15lenny2
  • OR linux-doc-2.6.26 is earlier than 2.6.26-15lenny2
  • OR linux-tree-2.6.26 is earlier than 2.6.26-15lenny2
  • OR linux-source-2.6.26 is earlier than 2.6.26-15lenny2
  • OR linux-manual-2.6.26 is earlier than 2.6.26-15lenny2
  • OR Architecture dependent section
  • Installed architecture is s390
  • AND Packages section
  • linux-headers-2.6.26-2-all is earlier than 2.6.26-15lenny2
  • OR linux-image-2.6.26-2-vserver-s390x is earlier than 2.6.26-15lenny2
  • OR linux-image-2.6.26-2-s390 is earlier than 2.6.26-15lenny2
  • OR linux-headers-2.6.26-2-s390 is earlier than 2.6.26-15lenny2
  • OR linux-image-2.6.26-2-s390-tape is earlier than 2.6.26-15lenny2
  • OR linux-headers-2.6.26-2-all-s390 is earlier than 2.6.26-15lenny2
  • OR linux-headers-2.6.26-2-vserver-s390x is earlier than 2.6.26-15lenny2
  • OR linux-headers-2.6.26-2-common-vserver is earlier than 2.6.26-15lenny2
  • OR linux-libc-dev is earlier than 2.6.26-15lenny2
  • OR linux-image-2.6.26-2-s390x is earlier than 2.6.26-15lenny2
  • OR linux-headers-2.6.26-2-common is earlier than 2.6.26-15lenny2
  • OR linux-headers-2.6.26-2-s390x is earlier than 2.6.26-15lenny2
  • OR Architecture dependent section
  • Installed architecture is amd64
  • AND Packages section
  • xen-linux-system-2.6.26-2-xen-amd64 is earlier than 2.6.26-15lenny2
  • OR linux-headers-2.6.26-2-all is earlier than 2.6.26-15lenny2
  • OR linux-modules-2.6.26-2-xen-amd64 is earlier than 2.6.26-15lenny2
  • OR linux-headers-2.6.26-2-openvz-amd64 is earlier than 2.6.26-15lenny2
  • OR linux-headers-2.6.26-2-common-vserver is earlier than 2.6.26-15lenny2
  • OR linux-image-2.6.26-2-openvz-amd64 is earlier than 2.6.26-15lenny2
  • OR linux-image-2.6.26-2-amd64 is earlier than 2.6.26-15lenny2
  • OR user-mode-linux is earlier than 2.6.26-1um-2+15lenny2
  • OR linux-headers-2.6.26-2-common-openvz is earlier than 2.6.26-15lenny2
  • OR linux-image-2.6.26-2-vserver-amd64 is earlier than 2.6.26-15lenny2
  • OR linux-headers-2.6.26-2-all-amd64 is earlier than 2.6.26-15lenny2
  • OR linux-image-2.6.26-2-xen-amd64 is earlier than 2.6.26-15lenny2
  • OR linux-headers-2.6.26-2-common-xen is earlier than 2.6.26-15lenny2
  • OR linux-libc-dev is earlier than 2.6.26-15lenny2
  • OR linux-headers-2.6.26-2-xen-amd64 is earlier than 2.6.26-15lenny2
  • OR linux-headers-2.6.26-2-amd64 is earlier than 2.6.26-15lenny2
  • OR linux-headers-2.6.26-2-common is earlier than 2.6.26-15lenny2
  • OR linux-headers-2.6.26-2-vserver-amd64 is earlier than 2.6.26-15lenny2
  • OR Supported platform section
  • Installed architecture is hppa
  • AND Packages section
  • linux-headers-2.6.26-2-all is earlier than 2.6.26-15lenny2
  • OR linux-headers-2.6.26-2-parisc is earlier than 2.6.26-15lenny2
  • OR linux-image-2.6.26-2-parisc64 is earlier than 2.6.26-15lenny2
  • OR linux-image-2.6.26-2-parisc is earlier than 2.6.26-15lenny2
  • OR linux-headers-2.6.26-2-parisc-smp is earlier than 2.6.26-15lenny2
  • OR linux-headers-2.6.26-2-all-hppa is earlier than 2.6.26-15lenny2
  • OR linux-headers-2.6.26-2-parisc64 is earlier than 2.6.26-15lenny2
  • OR linux-headers-2.6.26-2-parisc64-smp is earlier than 2.6.26-15lenny2
  • OR linux-libc-dev is earlier than 2.6.26-15lenny2
  • OR linux-image-2.6.26-2-parisc64-smp is earlier than 2.6.26-15lenny2
  • OR linux-headers-2.6.26-2-common is earlier than 2.6.26-15lenny2
  • OR linux-image-2.6.26-2-parisc-smp is earlier than 2.6.26-15lenny2
  • BACK