| CERT-In Advisory  
                                                                      CIAD-2008-0066sendmsg   and ATM subsystem Denial of Service Vulnerabilities in Linux KernelOriginal Issue Date: December  15, 2008
 Severity Rating: Medium
 Systems Affected  Overview Multiple vulnerabilities have been reported in Linux Kernel which could be exploited by local attacker to cause denial of service attack on the affected system. Description1. 'sendmsg  ' Denial of Service Vulnerability 
                                            
                                            
                                            	(
                                            		
                                            
                                                         
														CVE-2008-5300  
																							                                                                    
														 
												
												
													) 
 This vulnerability is caused due to "sendmsg  " not correctly blocking while the AF_UNIX garbage collector is running and triggers an OOM condition. This can be exploited by local attackers to cause denial of service via a large number of sendmsg   function calls.
 
 2. ATM Subsystem Denial of Service Vulnerability 
                                            
                                            
                                            	(
                                            		
                                            
                                                         
														CVE-2008-5079  
																							                                                                    
														 
												
												
													)
 
 A vulnerability is caused due to the "svc_listen  " function in net/atm/svc.c allowing users to create unassigned PVC/SVC entries by calling the function multiple times on a socket. The kernel goes into an infinite loop when it tries to display these unassigned entries by reading /proc/net/atm/*vc file, related to corruption of the vcc table.
 
 
 Solution Upgrade to latest versions provided by the vendor. http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.8
 http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=17b24b3c97498935a2ef9777370b1151dfed3f6f
 
 Vendor Informationkernel.org http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.8
 
 References kernel.org http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.8
 
 MLIST http://marc.info/?l=linux-netdev&m=122721862313564&w=2
 http://marc.info/?l=linux-netdev&m=122765505415944&w=2
 http://marc.info/?l=linux-netdev&m=122841256115780&w=2
 
 SecurityFocus http://www.securityfocus.com/bid/32516/
 http://www.securityfocus.com/archive/1/archive/1/498943/100/0/threaded
 
 Secunia http://secunia.com/advisories/32913/
 
 CVE NameDisclaimerCVE-2008-5300
 CVE-2008-5079
 
 The information provided herein is on "as is" basis, without warranty of any kind.Contact Information Email: info@cert-in.org.in  Phone: +91-11-24368572Postal address Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology
 Government of India
 Electronics Niketan
 6, CGO Complex, Lodhi Road,
 New Delhi - 110 003
 India
   |