Linux Kernel Get_Compat_Timespec和PTrace本地拒绝服务漏洞

漏洞信息详情

Linux Kernel Get_Compat_Timespec和PTrace本地拒绝服务漏洞

漏洞简介

Linux kernel 2.6.16-rc2及其早期版本,当运行于x86_64系统并且preemption有效时,本地用户可通过执行单步操作的多个ptrace任务来制造拒绝服务(oops),从而引起在do_debug函数调用期间的DEBUG_STACK堆栈崩溃。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

Linux kernel 2.6 -test6

Linux linux-2.6.15.2.tar.bz2

http://kernel.org/pub/linux/kernel/v2.6/linux-2.6.15.2.tar.bz2

Linux kernel 2.6 -test4

Linux linux-2.6.15.2.tar.bz2

http://kernel.org/pub/linux/kernel/v2.6/linux-2.6.15.2.tar.bz2

Linux kernel 2.6 -test2

Linux linux-2.6.15.2.tar.bz2

http://kernel.org/pub/linux/kernel/v2.6/linux-2.6.15.2.tar.bz2

Linux kernel 2.6 -test11

Linux linux-2.6.15.2.tar.bz2

http://kernel.org/pub/linux/kernel/v2.6/linux-2.6.15.2.tar.bz2

Linux kernel 2.6 -test9-CVS

Linux linux-2.6.15.2.tar.bz2

http://kernel.org/pub/linux/kernel/v2.6/linux-2.6.15.2.tar.bz2

Linux kernel 2.6

Linux linux-2.6.15.2.tar.bz2

http://kernel.org/pub/linux/kernel/v2.6/linux-2.6.15.2.tar.bz2

Linux kernel 2.6 -test3

Linux linux-2.6.15.2.tar.bz2

http://kernel.org/pub/linux/kernel/v2.6/linux-2.6.15.2.tar.bz2

Linux kernel 2.6 .10

Linux linux-2.6.15.2.tar.bz2

http://kernel.org/pub/linux/kernel/v2.6/linux-2.6.15.2.tar.bz2

Linux kernel 2.6 -test5

Linux linux-2.6.15.2.tar.bz2

http://kernel.org/pub/linux/kernel/v2.6/linux-2.6.15.2.tar.bz2

Linux kernel 2.6 -test1

Linux linux-2.6.15.2.tar.bz2

http://kernel.org/pub/linux/kernel/v2.6/linux-2.6.15.2.tar.bz2

Linux kernel 2.6 -test7

Linux linux-2.6.15.2.tar.bz2

http://kernel.org/pub/linux/kernel/v2.6/linux-2.6.15.2.tar.bz2

Linux kernel 2.6 -test9

Linux linux-2.6.15.2.tar.bz2

http://kernel.org/pub/linux/kernel/v2.6/linux-2.6.15.2.tar.bz2

Linux kernel 2.6 -test8

Linux linux-2.6.15.2.tar.bz2

http://kernel.org/pub/linux/kernel/v2.6/linux-2.6.15.2.tar.bz2

Linux kernel 2.6 -test10

Linux linux-2.6.15.2.tar.bz2

http://kernel.org/pub/linux/kernel/v2.6/linux-2.6.15.2.tar.bz2

Linux kernel 2.6.1 -rc1

Linux linux-2.6.15.2.tar.bz2

http://kernel.org/pub/linux/kernel/v2.6/linux-2.6.15.2.tar.bz2

Linux kernel 2.6.1 -rc2

Linux linux-2.6.15.2.tar.bz2

http://kernel.org/pub/linux/kernel/v2.6/linux-2.6.15.2.tar.bz2

Linux kernel 2.6.1

Linux linux-2.6.15.2.tar.bz2

http://kernel.org/pub/linux/kernel/v2.6/linux-2.6.15.2.tar.bz2

Linux kernel 2.6.10 rc2

Linux linux-2.6.15.2.tar.bz2

http://kernel.org/pub/linux/kernel/v2.6/linux-2.6.15.2.tar.bz2

Linux kernel 2.6.10

Linux linux-2.6.15.2.tar.bz2

http://kernel.org/pub/linux/kernel/v2.6/linux-2.6.15.2.tar.bz2

Ubuntu acpi-modules-2.6.10-6-386-di_2.6.10-34.17_i386.udeb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.10/acpi -modules-2.6.10-6-386-di_2.6.10-34.17_i386.udeb

Ubuntu acpi-modules-2.6.10-6-amd64-generic-di_2.6.10-34.17_amd64.udeb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.10/acpi -modules-2.6.10-6-amd64-generic-di_2.6.10-34.17_amd64.udeb

Ubuntu affs-modules-2.6.10-6-power3-di_2.6.10-34.17_powerpc.udeb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.10/affs -modules-2.6.10-6-power3-di_2.6.10-34.17_powerpc.udeb

Ubuntu affs-modules-2.6.10-6-power4-di_2.6.10-34.17_powerpc.udeb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.10/affs -modules-2.6.10-6-power4-di_2.6.10-34.17_powerpc.udeb

Ubuntu affs-modules-2.6.10-6-powerpc-di_2.6.10-34.17_powerpc.udeb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.10/affs -modules-2.6.10-6-powerpc-di_2.6.10-34.17_powerpc.udeb

Ubuntu cdrom-core-modules-2.6.10-6-386-di_2.6.10-34.17_i386.udeb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.10/cdro m-core-modules-2.6.10-6-386-di_2.6.10-34.17_i386.udeb

Ubuntu cdrom-core-modules-2.6.10-6-amd64-generic-di_2.6.10-34.17_amd64.udeb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.10/cdro m-core-modules-2.6.10-6-amd64-generic-di_2.6.10-34.17_amd64.udeb

Ubuntu cdrom-core-modules-2.6.10-6-power3-di_2.6.10-34.17_powerpc.udeb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/main/l/linux-source-2.6.10/cdro m-core-modules-2.6.10-6-power3-di_2.6.10-34.17_powerpc.udeb

Ubuntu cdro

参考网址

来源: BID

名称: 17216

链接:http://www.securityfocus.com/bid/17216

来源: OSVDB

名称: 24098

链接:http://www.osvdb.org/24098

来源: SECUNIA

名称: 19374

链接:http://secunia.com/advisories/19374

来源: DEBIAN

名称: DSA-1017

链接:http://www.debian.org/security/2006/dsa-1017

来源: MLIST

名称: [linux-kernel] 20060207 [PATCH] arch/x86_64/kernel/traps.c PTRACE_SINGLESTEP oops

链接:http://marc.theaimsgroup.com/?l=linux-kernel&m=113932292516359&w=2

来源: MLIST

名称: [linux-kernel] 20060207 [PATCH] arch/x86_64/kernel/traps.c PTRACE_SINGLESTEP oops

链接:http://marc.theaimsgroup.com/?l=linux-kernel&m=113932292516359&w=2

来源: UBUNTU

名称: USN-281-1

链接:http://www.ubuntulinux.org/support/documentation/usn/usn-281-1

来源: MANDRIVA

名称: MDKSA-2006:151

链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:151

来源: SECUNIA

名称: 21614

链接:http://secunia.com/advisories/21614

来源: SECUNIA

名称: 19955

链接:http://secunia.com/advisories/19955

来源: MANDRIVA

名称: MDKSA-2006:151

链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:151

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享