Release date:
Updated on:
Affected Systems:
Linux kernel 2.6.0-2.6.37
Description:
--------------------------------------------------------------------------------
Bugtraq id: 44301
Cve id: CVE-2010-3858
Linux Kernel is the Kernel used by open source Linux.
Linux Kernel has a vulnerability in implementation. Local attackers can exploit this vulnerability to cause system crash.
The CONFIG_STACK_GROWSDOWN variable of setup_arg_pages () does not check the size of the argument/environment region on the stack. If it is too large, shift_arg_pages () will hit its BUG_ON. The use of a very large RLIMIT_STACK limit can easily cause a system crash.
<Source: Roland McGrath (roland@redhat.com)
>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.kernel.org/