First published: Tue Sep 22 2009(Updated: )
The sg_build_indirect function in drivers/scsi/sg.c in Linux kernel 2.6.28-rc1 through 2.6.31-rc8 uses an incorrect variable when accessing an array, which allows local users to cause a denial of service (kernel OOPS and NULL pointer dereference), as demonstrated by using xcdroast to duplicate a CD. NOTE: this is only exploitable by users who can open the cdrom device.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | =2.6.31-rc6 | |
Linux Linux kernel | =2.6.31-rc10 | |
Linux Linux kernel | =2.6.31-rc4 | |
Linux Linux kernel | =2.6.31-rc5 | |
Linux Linux kernel | =2.6.31-rc3 | |
Linux Linux kernel | =2.6.31-rc8 | |
Linux Linux kernel | =2.6.31-rc2 | |
Kernel Linux Kernel | =2.6.28-rc1 | |
Linux Linux kernel | =2.6.31-rc9 | |
Linux Linux kernel | =2.6.31-rc7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.