PT-2009-1042 · Linux+2 · Linux Kernel+3
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 2.6.31-git11
Red Hat Enterprise Linux kernel versions 2.4.21
Description
The issue concerns multiple vulnerabilities in the Linux kernel and Red Hat Enterprise Linux kernel, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. Additionally, a local user can cause a denial of service or possibly gain privileges via unspecified ioctl calls due to the improper verification of Concurrent Command Engine (CCE) state initialization in the ATI Rage 128 driver.
Recommendations
For Linux kernel versions prior to 2.6.31-git11, update to version 2.6.31-git11 or later to resolve the issue.
For Red Hat Enterprise Linux kernel versions 2.4.21, consider disabling the vulnerable kernel modules or restricting access to them until a patch is available.
As a temporary workaround, consider disabling the ATI Rage 128 driver until a patch is available.
Correção
DoS
Use of Uninitialized Resource
NULL Pointer Dereference
Improper Validation of Array Index
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ati Rage 128
Linux Kernel
Red Hat
Red Hat Enterprise Linux Kernel