PublicDate: 2008-06-30 21:41:00 UTC Candidate: CVE-2008-2365 References: https://ubuntu.com/security/notices/USN-625-1 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2365 Description: Race condition in the ptrace and utrace support in the Linux kernel 2.6.9 through 2.6.25, as used in Red Hat Enterprise Linux (RHEL) 4, allows local users to cause a denial of service (oops) via a long series of PTRACE_ATTACH ptrace calls to another user's process that trigger a conflict between utrace_detach and report_quiescent, related to "late ptrace_may_attach() check" and "race around &dead_engine_ops setting," a different vulnerability than CVE-2007-0771 and CVE-2008-1514. NOTE: this issue might only affect kernel versions before 2.6.16.x. Ubuntu-Description: A race condition was discovered between ptrace and utrace in the kernel. A local attacker could exploit this to crash the system, leading to a denial of service. Notes: Bugs: Priority: medium Discovered-by: Assigned-to: kees CVSS: Patches_linux-source-2.6.15: upstream: linux-2.6: 5ecfbae093f0c37311e89b29bfc0c9d586eace87 (N/A) upstream: linux-2.6: f5b40e363ad6041a96e3da32281d8faa191597b9 upstream: linux-2.6: f358166a9405e4f1d8e50d8f415c26d95505b6de upstream_linux-source-2.6.15: not-affected dapper_linux-source-2.6.15: released (2.6.15-52.69) feisty_linux-source-2.6.15: DNE gutsy_linux-source-2.6.15: DNE hardy_linux-source-2.6.15: DNE devel_linux-source-2.6.15: DNE Patches_linux-source-2.6.20: upstream_linux-source-2.6.20: not-affected dapper_linux-source-2.6.20: DNE feisty_linux-source-2.6.20: not-affected gutsy_linux-source-2.6.20: DNE hardy_linux-source-2.6.20: DNE devel_linux-source-2.6.20: DNE Patches_linux-source-2.6.22: upstream_linux-source-2.6.22: not-affected dapper_linux-source-2.6.22: DNE feisty_linux-source-2.6.22: DNE gutsy_linux-source-2.6.22: not-affected hardy_linux-source-2.6.22: DNE devel_linux-source-2.6.22: DNE Patches_linux: upstream_linux: not-affected dapper_linux: DNE feisty_linux: DNE gutsy_linux: DNE hardy_linux: not-affected devel_linux: not-affected