漏洞信息详情
Linux Kernel Futex本地死锁拒绝服务漏洞
漏洞简介
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。NFSv4 implementation是其中的一个分布式文件系统协议。
Linux kernel 2.6.x的futex.c中的某些futex函数,在执行get_user调用的同时会保留mmap_sem信号灯,这可让本地用户通过在其他线程正在执行mmap或其他函数时触发get_user错误来导致do_page_fault中产生死锁条件。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Linux kernel 2.6.8 rc1
Ubuntu linux-doc-2.6.8.1_2.6.8.1-16.14_all.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.8.1/lin ux-doc-2.6.8.1_2.6.8.1-16.14_all.deb
Ubuntu linux-headers-2.6.8.1-5-386_2.6.8.1-16.14_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.8.1/lin ux-headers-2.6.8.1-5-386_2.6.8.1-16.14_i386.deb
Ubuntu linux-headers-2.6.8.1-5-686-smp_2.6.8.1-16.14_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.8.1/lin ux-headers-2.6.8.1-5-686-smp_2.6.8.1-16.14_i386.deb
Ubuntu linux-headers-2.6.8.1-5-686_2.6.8.1-16.14_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.8.1/lin ux-headers-2.6.8.1-5-686_2.6.8.1-16.14_i386.deb
Ubuntu linux-headers-2.6.8.1-5-amd64-generic_2.6.8.1-16.14_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.8.1/lin ux-headers-2.6.8.1-5-amd64-generic_2.6.8.1-16.14_amd64.deb
Ubuntu linux-headers-2.6.8.1-5-amd64-k8-smp_2.6.8.1-16.14_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.8.1/lin ux-headers-2.6.8.1-5-amd64-k8-smp_2.6.8.1-16.14_amd64.deb
Ubuntu linux-headers-2.6.8.1-5-amd64-k8_2.6.8.1-16.14_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.8.1/lin ux-headers-2.6.8.1-5-amd64-k8_2.6.8.1-16.14_amd64.deb
Ubuntu linux-headers-2.6.8.1-5-amd64-xeon_2.6.8.1-16.14_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.8.1/lin ux-headers-2.6.8.1-5-amd64-xeon_2.6.8.1-16.14_amd64.deb
Ubuntu linux-headers-2.6.8.1-5-k7-smp_2.6.8.1-16.14_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.8.1/lin ux-headers-2.6.8.1-5-k7-smp_2.6.8.1-16.14_i386.deb
Ubuntu linux-headers-2.6.8.1-5-k7_2.6.8.1-16.14_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.8.1/lin ux-headers-2.6.8.1-5-k7_2.6.8.1-16.14_i386.deb
Ubuntu linux-headers-2.6.8.1-5-power3-smp_2.6.8.1-16.14_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.8.1/lin ux-headers-2.6.8.1-5-power3-smp_2.6.8.1-16.14_powerpc.deb
Ubuntu linux-headers-2.6.8.1-5-power3_2.6.8.1-16.14_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.8.1/lin ux-headers-2.6.8.1-5-power3_2.6.8.1-16.14_powerpc.deb
Ubuntu linux-headers-2.6.8.1-5-power4-smp_2.6.8.1-16.14_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.8.1/lin ux-headers-2.6.8.1-5-power4-smp_2.6.8.1-16.14_powerpc.deb
Ubuntu linux-headers-2.6.8.1-5-power4_2.6.8.1-16.14_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.8.1/lin ux-headers-2.6.8.1-5-power4_2.6.8.1-16.14_powerpc.deb
Ubuntu linux-headers-2.6.8.1-5-powerpc-smp_2.6.8.1-16.14_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.8.1/lin ux-headers-2.6.8.1-5-powerpc-smp_2.6.8.1-16.14_powerpc.deb
Ubuntu linux-headers-2.6.8.1-5-powerpc_2.6.8.1-16.14_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.8.1/lin ux-headers-2.6.8.1-5-powerpc_2.6.8.1-16.14_powerpc.deb
Ubuntu linux-headers-2.6.8.1-5_2.6.8.1-16.14_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.8.1/lin ux-headers-2.6.8.1-5_2.6.8.1-16.14_amd64.deb
Ubuntu linux-headers-2.6.8.1-5_2.6.8.1-16.14_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.8.1/lin ux-headers-2.6.8.1-5_2.6.8.1-16.14_i386.deb
Ubuntu linux-headers-2.6.8.1-5_2.6.8.1-16.14_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/
参考网址
来源: MISC
链接:http://lkml.org/lkml/2005/2/22/123
来源: linux.bkbits.net:8080
链接:http://linux.bkbits.net:8080/linux-2.6/cset@421cfc11zFsK9gxvSJ2t__FCmuUd3Q
来源: FEDORA
名称: FLSA:157459-3
链接:http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded
来源: REDHAT
名称: RHSA-2005:420
链接:http://www.redhat.com/support/errata/RHSA-2005-420.html
受影响实体
- Linux Linux_kernel:2.5.65<!--2000-1-1-->
- Linux Linux_kernel:2.5.11<!--2000-1-1-->
- Linux Linux_kernel:2.5.12<!--2000-1-1-->
- Linux Linux_kernel:2.5.8<!--2000-1-1-->
- Linux Linux_kernel:2.5.9<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...