Linux Kernel do_mremap Function VMA Limit Local Privilege Escalation Vulnerability Solution:
SmoothWall have released an advisory (SWL-2004:002) and fixes to address this issue in SmoothWall Corporate Server 3.0(fixes7) and Corporate Guardian 3.0(fixes2). Please see referenced advisory for additional details regarding obtaining and applying appropriate fixes. Fixes are linked below.
Mandrake has released an advisory (MDKSA-2004:015) with fixes to address this issue. Please see the referenced advisory for more information.
Trustix has released an advisory TSLSA-2004-0008 with fixes to address this issue. Please see the referenced advisory for more information.
Turbolinux has released an advisory TLSA-2004-7 with fixes to address this issue. Please see the referenced advisory for more information.
RedHat has released an advisory RHSA-2004:065-01 with fixes to address this issue. Please see the referenced advisory for more information.
Trustix has released an advisory TSLSA-2004-0007 with fixes to address this issue. Please see the referenced advisory for more information.
Slackware has released an advisory SSA:2004-049-01 with fixes to address this issue. Please see the referenced advisory for more information.
Debian has released multiple advisories DSA-439-1, DSA-440-1, DSA-438-1 with fixes to address this issue. Please see the referenced advisories for more information.
Debian has released an advisory DSA-441-1 with fixes to address this issue. Please see the referenced advisory for more information.
RedHat has released an advisory FEDORA-2004-079 with fixes to address this issue. Please see the referenced advisory for more information.
SuSE has released advisory SA:2004:005 dealing with this issue. Please see the referenced advisory for more information.
Debian has released DSA 442-1 to provide fixes for s390 platforms. Please see the attached advisory for further information.
RedHat has released an updated advisory FEDORA-2004-080 with fixes to address this issue. Please see the referenced advisory for more information.
Debian has released DSA 444-1 to provide fixes for ia64 platforms. Please see the attached advisory for further information.
Conectiva has released advisory CLA-2004:820 dealing with this issue. Please see the referenced advisory for more information.
Netwosix advisory 2004-0002 has been released dealing with this issue. Please see below for fixes and the reference section for the advisory text.
Mandrake has released an updated advisory MDKSA-2004:015-1 to address this and other issues. Please see the referenced advisory for more information.
SmoothWall Project has released an advisory SWP-2004:002 to address this issue in SmoothWall Express 2.0. Please see the referenced advisory for more information.
SGI has released an advisory 20040204-01-U to address this and other issues in SGI ProPack 2.4. Please see the referenced advisory for more information.
Immunix advisory IMNX-2004-7+-001-01 was released to provide updates for this issue.
Debian has released DSA 450-1 to provide MIPS kernel fixes. Please see the attached advisory for further details.
Debian has released advisory DSA 453-1 providing kernel fixes for the i386, m68k and PowerPC architectures. Please see the attached advisory for details.
Debian has released advisory DSA 454-1 providing kernel fixes for the alpha architecture. Please see the attached advisory for details.
Fedora has released legacy advisory update FLSA:1284 fixing this issue in Red Hat linux 7.2, 7.3 and 8.0 for the i386, i586, i686 and athlon architectures. Please see the referenced advisory for details.
Debian has released DSA 456-1 with updates for 2.2.19 (arm) kernels. Please see the attached advisory for details on obtaining and applying fixes.
Gentoo has released advisory GLSA 200403-02 to address this issue. Detailed upgrade instructions may be found in the attached advisory.
Devil-Linux 1.0.5 was released to address this issue.
Debian has released DSA 466-1 with updates for 2.2.10 (ppc) kernels. Please see the attached advisory for details on obtaining and applying fixes.
Debian has released DSA 470-1 to address this and other issues in the HP Precision architecture. Please see the referenced advisory for more information.
VMWare advisory and fixes available for their ESX server package. Please see th reference section for more information.
Debian has released advisory DSA 475-1 with fixes dealing with this and other issues for the HP Precision architecture.
Debian has released advisory DSA 514-1 with fixes dealing with this issue for the SPARC architecture. Please see the referenced advisory for more information.
Fixes available:
RedHat kernel-2.4.20-8.athlon.rpm
RedHat kernel-2.4.20-8.i386.rpm
RedHat kernel-smp-2.4.20-8.i686.rpm
RedHat kernel-BOOT-2.4.20-8.i386.rpm
RedHat kernel-bigmem-2.4.20-8.i686.rpm
RedHat kernel-source-2.4.20-8.i386.rpm
RedHat kernel-2.4.20-8.i686.rpm
SmoothWall Corporate Server 0.3 (Fixes7)
SmoothWall Corporate Guardian 0.3 (Fixes2)
VMWare ESX Server 2.0
VMWare ESX Server 2.0.1
Linux kernel 2.2.19
Linux kernel 2.2.20
Linux kernel 2.4.17
Linux kernel 2.4.18
Linux kernel 2.4.19
Linux kernel 2.4.21
Linux kernel 2.4.22
Linux kernel 2.4.23
Linux kernel 2.4.5
Linux kernel 2.4.9