|
|
|
![]() |
Vulnerability Note VU#490620Linux kernel do_mremap() call creates virtual memory area of 0 bytes in lengthOverviewThere is a vulnerability in the Linux kernel memory management routines that allows local users to gain superuser privileges.I. DescriptionThe Linux kernel contains a vulnerability in the do_mremap() call that allows software to create a virtual memory area (VMA) with a length of 0 bytes. This vulnerability is reported to exist in versions 2.4.23 and earlier, excluding 2.2.x versions. Because the vulnerability is located within the kernel, multiple Linux distributions will be affected. An attacker with local access to an affected host may be able to exploit this vulnerability and gain superuser privileges.II. ImpactThis vulnerability allows local users to gain superuser privileges on affected hosts.III. SolutionApply a patch from your vendorThis vulnerability affects multiple Linux distributions; please see the Systems Affected section of this document for information on specific vendors.
References
This vulnerability was discovered by Paul Starzetz. This document was written by Jeffrey P. Lanza.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||