Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Linux Kernel Futex Local Deadlock Denial Of Service Vulnerability

The Linux kernel futex functions are reported prone to a local denial of service vulnerability. The issue is reported to manifest because several unspecified futex functions perform 'get_user()' calls and at the same time hold mmap_sem for reading purposes.

A local attacker may potentially leverage this issue to trigger a kernel deadlock and potentially deny service for legitimate users.

This vulnerability is reported to exist in the 2.6 Linux kernel tree.







 

Privacy Statement
Copyright 2008, SecurityFocus