imPC@ndo IT

Tracker / CVE-2009-1961

CVE-2009-1961

Medium 4.7

The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of file creation and removal) via a series of splice system calls that trigger a deadlock between the generic_file_splice_write, splice_from_pipe, and ocfs2_file_splice_write functions.

Affected products and versions

canonical ubuntu_linux
debian debian_linux
linux linux_kernel
linux linux_kernel · … → 2.6.19
linux linux_kernel · 2.6.27 → 2.6.27.24
linux linux_kernel · 2.6.29 → 2.6.29.4
opensuse opensuse
suse linux_enterprise
suse linux_enterprise_desktop
suse linux_enterprise_server

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References