Sun Microsystems Inc. Information for VU#683673

Sun Solaris priocntl(2) does not adequately validate path to kernel modules that implement lightweight process (LWP) scheduling policy



Vendor Statement

Sun confirms that the priocntl(2) vulnerability does affect all currently supported versions of Solaris:

    Solaris 2.6, 7, 8, and 9

Sun has released a Sun Alert which describes a workaround until patches are available at:
The Sun Alert will be updated with the patch information once it becomes available. Sun patches are available from:

    Vendor Information

    The vendor has not provided us with any further information regarding this vulnerability.

    Vendor References



    The CERT/CC has no additional comments at this time.

    If you have feedback, comments, or additional information about this vulnerability, please send us email.