blob: 2d8276a4cff6bf8b73c2df0ebc6235f233280fa0 (plain
Linux kernel 2.4 and 2.6 allows attackers to cause a denial of service
(memory exhaustion and panic) by creating a large number of connected
file descriptors or socketpairs and setting a large data transfer
buffer, then preventing Linux from being able to finish the transfer
by causing the process to become a zombie, or closing the file
descriptor without closing an associated reference.
5~ dannf> The fix suggested by idefense includes adding a struct user reference
dannf> to struct file. No such thing has gone upstream yet, however.
2.6.8-sarge-security: ignored (2.6.8-16sarge5)
2.4.27-sarge-security: ignored (2.4.27-10sarge4)