Wind River Support Network

HomeOther DownloadsSecurity Advisory - Linux - CVE-2006-7051
Recommended Type: Patch

Security Advisory - Linux - CVE-2006-7051

Released: Apr 28, 2009     Updated: Apr 28, 2009

Description

The sys_timer_create function in posix-timers.c for Linux kernel 2.6.x allows local users to cause a denial of service (memory consumption) and possibly bypass memory limits or cause other processes to be killed by creating a large number of posix timers, which are allocated in kernel memory but are not treated as part of the process' memory.


Product Version

Linux Platforms 1.x

Downloads


Installation Notes

Installation Notes

WIND00158964.zip is for 1.4
WIND00158972.zip is for 1.5
1. Unzip the patch under [install_dir]/updates 
2. Install the patch CD by entering the patch CD directory and run setup_linux. 
3. This is a source only patch so you will have to build the kernel 
4. Issue a make fs and make the kernel in a configured directory. 
5. Upload the kernel and rootfs into the target and boot it up.


Live chat
Online