Release date: 2010-09-02
Updated on: 2010-09-03
Affected Systems:
Linux kernel 2.6.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 42932
Cve id: CVE-2010-2960
Linux Kernel is the Kernel used by open source Linux.
Linux Kernel security/keys/keyctl. the keyctl_session_to_parent () function in the c file has a null pointer application error. Local users can use KEYCTL_SESSION_TO_PARENT to call keyctl () to trigger this vulnerability, resulting in DOS.
<* Source: Tavis Ormandy (taviso@gentoo.org)
Link: http://secunia.com/advisories/41263/
Https://bugzilla.redhat.com/show_bug.cgi? Format = multiple & amp; id = 627440
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.kernel.org/