The Linux kernel 2.6.24 and 2.6.25 before 2.6.25.9 allows local users to cause a denial of service (memory consumption) via a large number of calls to the get_user_pages function, which lacks a ZERO_PAGE optimization and results in allocation of "useless newly zeroed pages."
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:46
Type | Values Removed | Values Added |
---|---|---|
References | () http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=89f5b7da2a6bad2e84670422ab8192382a5aeb9f - | |
References | () http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.9 - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00007.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00009.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00012.html - | |
References | () http://new-ubuntu-news.blogspot.com/2008/06/re-pending-stable-kernel-security_25.html - | |
References | () http://secunia.com/advisories/30901 - | |
References | () http://secunia.com/advisories/30982 - | |
References | () http://secunia.com/advisories/31202 - | |
References | () http://secunia.com/advisories/31628 - | |
References | () http://secunia.com/advisories/32393 - | |
References | () http://secunia.com/advisories/32485 - | |
References | () http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0207 - | |
References | () http://www.redhat.com/support/errata/RHSA-2008-0585.html - | |
References | () http://www.redhat.com/support/errata/RHSA-2008-0957.html - | |
References | () http://www.ubuntu.com/usn/usn-659-1 - | |
References | () http://www.ussg.iu.edu/hypermail/linux/kernel/0804.3/3203.html - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/43550 - | |
References | () https://issues.rpath.com/browse/RPL-2629 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9383 - |
Information
Published : 2008-07-02 16:41
Updated : 2024-11-21 00:46
NVD link : CVE-2008-2372
Mitre link : CVE-2008-2372
CVE.ORG link : CVE-2008-2372
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-20
Improper Input Validation