First published: Wed Feb 28 2007(Updated: )
The file watch implementation in the audit subsystem (auditctl -w) in the Red Hat Enterprise Linux (RHEL) 4 kernel 2.6.9 allows local users to cause a denial of service (kernel panic) by replacing a watched file, which does not cause the watch on the old inode to be dropped.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Enterprise Linux | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0001 has a medium severity level due to its potential for causing a denial of service through kernel panic.
To fix CVE-2007-0001, consider applying the latest patches and updates provided by Red Hat for your RHEL 4 system.
CVE-2007-0001 affects local users of Red Hat Enterprise Linux 4 running kernel 2.6.9.
CVE-2007-0001 is a local denial of service vulnerability that exploits the file watch feature in the audit subsystem.
If CVE-2007-0001 is exploited, it can lead to a kernel panic, causing the system to become unresponsive.