Memory leak in the VFS file lease handling in locks.c in Linux kernels 2.6.10 to 2.6.15 allows local users to cause a denial of service (memory exhaustion) via certain Samba activities that cause an fasync entry to be re-allocated by the fcntl_setlease function after the fasync queue has already been cleaned by the locks_delete_lock function.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Ubuntu | — | Upgrade linux-image-2.6.10-6-k7-smpUpgrade linux-image-2.6.8.1-6-686-smpUpgrade linux-image-2.6.12-10-k7Upgrade linux-image-2.6.10-6-686-smpUpgrade linux-image-2.6.8.1-6-amd64-k8-smpUpgrade linux-image-2.6.10-6-powerpcUpgrade linux-image-2.6.8.1-6-686Upgrade linux-image-2.6.8.1-6-k7Upgrade linux-image-2.6.8.1-6-k7-smpUpgrade linux-image-2.6.8.1-6-power4-smpUpgrade linux-image-2.6.12-10-amd64-xeonUpgrade linux-image-2.6.10-6-amd64-xeonUpgrade linux-patch-ubuntu-2.6.10Upgrade linux-image-2.6.10-6-mckinley-smpUpgrade linux-patch-ubuntu-2.6.12Upgrade linux-image-2.6.8.1-6-amd64-k8Upgrade linux-image-2.6.10-6-powerpc-smpUpgrade linux-image-2.6.10-6-k7Upgrade linux-image-2.6.8.1-6-power3Upgrade linux-image-2.6.12-10-k7-smpUpgrade linux-image-2.6.10-6-mckinleyUpgrade linux-image-2.6.8.1-6-386Upgrade linux-image-2.6.10-6-power3-smpUpgrade linux-image-2.6.10-6-power4-smpUpgrade linux-image-2.6.12-10-amd64-generic | Nov 8, 2024 | Nov 25, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub