Release date:
Updated on: 2012-06-01
Affected Systems:
Linux kernel 2.6.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53414
CVE (CAN) ID: CVE-2012-2100
Linux Kernel is the Kernel of the Linux operating system.
Linux Kernel has a local denial of service vulnerability in the implementation of the ext4_fill_flex_info () function. s_log_groups_per_flex can be set to a forged value. Attackers can exploit this vulnerability to trigger a Kernel crash.
<* Source: vendor
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 809687
Http://git.kernel.org /? P = linux/kernel/git/torvalds/linux-2.6.git; a = commitdiff; h = d50f2ab6f050311dbf7b8f5501b25f0bf64a439b
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.kernel.org/