The console selection feature in the Linux kernel 2.6.28 before 2.6.28.4, 2.6.25, and possibly earlier versions, when the UTF-8 console is used, allows physically proximate attackers to cause a denial of service (memory corruption) by selecting a small number of 3-byte UTF-8 characters, which triggers an "off-by-two memory error." NOTE: it is not clear whether this issue crosses privilege boundaries.
CVSS Details
- CVSS 3.1 Base Score: 6.2
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade kernel-xenUpgrade iscsitarget-kmp-debugUpgrade atl2-kmp-debugUpgrade wlan-ng-kmp-debugUpgrade kernel-kdumpUpgrade kernel-debugUpgrade kqemu-kmp-debugUpgrade omnibook-kmp-debugUpgrade dazuko-kmp-debugUpgrade kernel-paeUpgrade at76_usb-kmp-debugUpgrade acx-kmp-debugUpgrade pcc-acpi-kmp-debugUpgrade gspcav-kmp-debugUpgrade appleir-kmp-debugUpgrade kernel-symsUpgrade aufs-kmp-debugUpgrade kernel-defaultUpgrade kernel-sourceUpgrade kernel-ppc64Upgrade kernel-docsUpgrade nouveau-kmp-debugUpgrade pcfclock-kmp-debugUpgrade drbd-kmp-debugUpgrade virtualbox-ose-kmp-debugUpgrade kernel-xenpaeUpgrade kernel-ps3Upgrade uvcvideo-kmp-debugUpgrade acerhk-kmp-debugUpgrade vmware-kmp-debugUpgrade ivtv-kmp-debugUpgrade tpctl-kmp-debugUpgrade kernel-vanilla | Feb 17, 2015 | Mar 23, 2009 |
| Ubuntu | — | Upgrade linux-image-2.6.24-23-xenUpgrade linux-image-2.6.22-16-virtualUpgrade linux-image-2.6.22-16-lpiaUpgrade linux-image-2.6.22-16-sparc64Upgrade linux-image-2.6.24-23-hppa32Upgrade linux-image-2.6.22-16-serverUpgrade linux-image-2.6.22-16-rtUpgrade linux-image-2.6.24-23-386Upgrade linux-image-2.6.22-16-genericUpgrade linux-image-2.6.22-16-mckinleyUpgrade linux-image-2.6.24-23-rtUpgrade linux-image-2.6.22-16-hppa32Upgrade linux-image-2.6.24-23-openvzUpgrade linux-image-2.6.22-16-xenUpgrade linux-image-2.6.24-23-genericUpgrade linux-image-2.6.22-16-itaniumUpgrade linux-image-2.6.22-16-sparc64-smpUpgrade linux-image-2.6.24-23-hppa64Upgrade linux-image-2.6.27-11-genericUpgrade linux-image-2.6.24-23-itaniumUpgrade linux-image-2.6.24-23-sparc64Upgrade linux-image-2.6.22-16-powerpc-smpUpgrade linux-image-2.6.22-16-386Upgrade linux-image-2.6.24-23-lpiaUpgrade linux-image-2.6.24-23-powerpc-smpUpgrade linux-image-2.6.24-23-sparc64-smpUpgrade linux-image-2.6.22-16-lpiacompatUpgrade linux-image-2.6.24-23-powerpc64-smpUpgrade linux-image-2.6.22-16-powerpcUpgrade linux-image-2.6.27-11-virtualUpgrade linux-image-2.6.24-23-powerpcUpgrade linux-image-2.6.22-16-powerpc64-smpUpgrade linux-image-2.6.22-16-umeUpgrade linux-image-2.6.24-23-virtualUpgrade linux-image-2.6.22-16-hppa64Upgrade linux-image-2.6.24-23-serverUpgrade linux-image-2.6.22-16-cellUpgrade linux-image-2.6.27-11-serverUpgrade linux-image-2.6.24-23-lpiacompatUpgrade linux-image-2.6.24-23-mckinley | Nov 8, 2024 | Mar 23, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub