Release date: 2011-11-14
Updated on: 2011-11-15
Affected Systems:
Linux kernel 2.6.x
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2011-4132
Linux is the kernel of a free computer.
Linux Kernel has two implementation vulnerabilities that can be exploited by local users to cause DOS.
The vulnerability is caused by the "journal_get_superblock ()" function (fs/jbd/journal. c and fs/jbd2/journal. c), you can trigger "BUG_ON ()" by loading a special ext3 image ()".
<* Source: Eryu Guan
Link: http://git.kernel.org /? P = linux/kernel/git/torvalds/linux-2.6.git; a = commitdiff; h = 8762202dd0d6e46854f786bdb6fb3780a1625efe
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.kernel.org/