[Full-Disclosure] RE: i386 Linux kernel DoS (fixed)

From: Leif Sawyer (lsawyerat_private)
Date: Thu Nov 14 2002 - 11:42:06 PST

  • Next message: mattmurphyat_private: "[VulnWatch] Perception LiteServe HTTP CGI Disclosure Vulnerability"

    The fix for 2.4 kernels was posted today by Alan Cox:
    
    Linux 2.4.20-rc1-ac2
    o	Ptrace NT flag fix				(Andrea Arcangeli)
    o	lcall NT clear fixes				(Petr Vandrovec)
    [...]
    
    
    > -----Original Message-----
    > From: Christophe Devine writes:
    > 
    > Yep; the first version of the DoS I posted on bugtraq was 
    > defective and worked only under special conditions (inside
    > gdb for example).
    [code snipped]
    > 
    > At the beginning I thought only kernels <= 2.4.18 were 
    > affected; but it appeared that both kernels 2.4.19 and
    > 2.4.20-rc1 are vulnerable as well.
    >
    > The flaw seems to be related to the kernel's handling of the 
    > nested task (NT) flag inside a lcall7. 
    > 
    > -- 
    > Christophe Devine
    > 
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    



    This archive was generated by hypermail 2b30 : Thu Nov 14 2002 - 12:07:21 PST