Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!Close

CVE-2011-1759

Published: 2 May 2011

Integer overflow in the sys_oabi_semtimedop function in arch/arm/kernel/sys_oabi-compat.c in the Linux kernel before 2.6.39 on the ARM platform, when CONFIG_OABI_COMPAT is enabled, allows local users to gain privileges or cause a denial of service (heap memory corruption) by providing a crafted argument and leveraging a race condition.

From the Ubuntu Security Team

Dan Rosenberg reported an error in the old ABI compatibility layer of ARM kernels. A local attacker could exploit this flaw to cause a denial of service or gain root privileges.

Priority

Low

Status

Package Release Status
linux
Launchpad, Ubuntu, Debian
hardy Not vulnerable
(ARM specific issue)
lucid
Released (2.6.32-33.64)
maverick
Released (2.6.35-32.64)
natty
Released (2.6.38-10.44)
oneiric Not vulnerable
(2.6.39-1.6)
precise Not vulnerable
(3.1.0-1.1)
quantal Not vulnerable
(3.1.0-1.0)
upstream
Released (2.6.39~rc6)
Patches:
Introduced by

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

Fixed by 0f22072ab50cac7983f9660d33974b45184da4f9
linux-armadaxp
Launchpad, Ubuntu, Debian
hardy Does not exist

lucid Does not exist

natty Does not exist

oneiric Does not exist

precise Not vulnerable
(3.2.0-1600.1)
quantal Not vulnerable
(3.2.0-1602.5)
upstream
Released (2.6.39~rc6)
linux-ec2
Launchpad, Ubuntu, Debian
hardy Does not exist

lucid
Released (2.6.32-317.32)
maverick Ignored
(end of life)
natty Does not exist

oneiric Does not exist

precise Does not exist

quantal Does not exist

upstream
Released (2.6.39~rc6)
linux-fsl-imx51
Launchpad, Ubuntu, Debian
hardy Does not exist

lucid Not vulnerable
(CONFIG_OABI_COMPAT is not set)
maverick Does not exist

natty Does not exist

oneiric Does not exist

precise Does not exist

quantal Does not exist

upstream
Released (2.6.39~rc6)
linux-lts-backport-maverick
Launchpad, Ubuntu, Debian
hardy Does not exist

lucid
Released (2.6.35-32.64~lucid1)
maverick Does not exist

natty Does not exist

oneiric Does not exist

precise Does not exist

quantal Does not exist

upstream
Released (2.6.39~rc6)
linux-lts-backport-natty
Launchpad, Ubuntu, Debian
hardy Does not exist

lucid Not vulnerable
(2.6.38-10.44~lucid1)
maverick Does not exist

natty Does not exist

oneiric Does not exist

precise Does not exist

quantal Does not exist

upstream
Released (2.6.39~rc6)
linux-lts-backport-oneiric
Launchpad, Ubuntu, Debian
hardy Does not exist

lucid Not vulnerable
(3.0.0-5.6~lucid1)
maverick Does not exist

natty Does not exist

oneiric Does not exist

precise Does not exist

quantal Does not exist

upstream
Released (2.6.39~rc6)
linux-mvl-dove
Launchpad, Ubuntu, Debian
hardy Does not exist

lucid
Released (2.6.32-217.34)
maverick
Released (2.6.32-417.34)
natty Does not exist

oneiric Does not exist

precise Does not exist

quantal Does not exist

upstream
Released (2.6.39~rc6)
linux-ti-omap4
Launchpad, Ubuntu, Debian
hardy Does not exist

lucid Does not exist

maverick
Released (2.6.35-903.31)
natty
Released (2.6.38-1209.22)
oneiric Not vulnerable
(3.0.0-1200.1)
precise Not vulnerable
(3.0.0-1401.2)
quantal Not vulnerable
(3.0.0-1401.2)
upstream
Released (2.6.39~rc6)