Linux kernel has vulnerabilities in processing sockets that could be exploited by a local attacker to cause a denial-of-service attack on the server.
Detailed Description:
Linux kernel is the kernel used by OSS Linux. Linux kernel has vulnerabilities in processing sockets that could be exploited by a local attacker to cause a denial-of-service attack on the server. Linux kernel lacks checks on the source when buffering data transmitted over a pair of sockets. An attacker could open a number of connection file descriptors or socket pairs and create the largest kernel buffer for data transferred between two sockets. If you can cause a process to enter a zombie (zombie) state or close a file descriptor while keeping the reference open, the data is kept in kernel until the transfer completes. Repeated attacks can result in the exhaustion of system memory resources.
Affected Systems:
Linux Kernel 2.6.12
Linux Kernel 2.4.22
Patch Download:
http://www.kernel.org/