Sun Microsystems Inc. Information for VU#683673

Sun Solaris priocntl(2) does not adequately validate path to kernel modules that implement lightweight process (LWP) scheduling policy

Status

Affected

Vendor Statement

Sun confirms that the priocntl(2) vulnerability does affect all currently supported versions of Solaris:

    Solaris 2.6, 7, 8, and 9

Sun has released a Sun Alert which describes a workaround until patches are available at:
The Sun Alert will be updated with the patch information once it becomes available. Sun patches are available from:
    http://sunsolve.sun.com/securitypatch

    Vendor Information

    The vendor has not provided us with any further information regarding this vulnerability.

    Vendor References

    None

    Addendum

    The CERT/CC has no additional comments at this time.

    If you have feedback, comments, or additional information about this vulnerability, please send us email.