First published: Mon Dec 21 2009(Updated: )
Created <span class=""><a href="attachment.cgi?id=379640" name="attach_379640" title="">attachment 379640</a> <a href="attachment.cgi?id=379640&action=edit" title="">[details]</a></span> Program to panic the kernel via fuse Description of problem: There is a problem in the ioctl handler in the fuse kernel code that causes a panic under some circumstances. Version-Release number of selected component (if applicable): fuse-2.8.1-1.fc11.i586 kernel-2.6.30.9-102.fc11.i586 How reproducible: Run the attached program on a fuse filesystem. The kernel should panic. Additional info: This seems to have been fixed upstream already: <a href="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=0bd87182d3ab18a32a8e9175d3f68754c58e3432">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=0bd87182d3ab18a32a8e9175d3f68754c58e3432</a> I've checked the 'security' bugzilla bit as it's easy for a regular user to bring the machine down with this.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Fuse | ||
Red Hat Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-549400 is high due to its potential to panic the kernel.
To fix REDHAT-BUG-549400, you should apply the latest updates provided by Red Hat for the affected software.
REDHAT-BUG-549400 affects the Red Hat FUSE and Red Hat Linux kernel.
Yes, REDHAT-BUG-549400 may be exploitable remotely if an attacker can send malicious requests to the system.
If REDHAT-BUG-549400 is not addressed, it could lead to system instability and unexpected crashes.