Linux Kernel Array Bounds Checking Vulnerability
RISK: Medium Risk
TYPE: Operating Systems - Linux
A vulnerability has been identified in the Linux Kernel. A local user can obtain elevated privileges on the target system.
On systems compiled with PERF_EVENTS support, a local user can supply a specially crafted perf_event_open() call to execute arbitrary code on the target system with root privileges.
The vulnerability resides in the perf_swevent_init() function in 'kernel/events/core.c'.
Impact
- Elevation of Privilege
System / Technologies affected
- 2.6.37 to 3.8.9
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix (3.8.9rc8).
Vulnerability Identifier
Source
Related Link
Share with