Linux Kernel contains a flaw that may allow a local denial of service. The issue is triggered when the 'wait_for_unix_gc' function in 'net/unix/garbage.c' fails to properly select times for garbage collection of inflight sockets, allowing a local attacker to cause a denial of service via the 'socketpair' and 'sendmsg' system calls for SOCK_SEQPACKET sockets.
Classification
Location:
Local Access Required
Attack Type:
Denial of Service
Impact:
Loss of Availability
Solution:
Upgrade
Exploit:
Exploit Public
Disclosure:
Vendor Verified
Solution
Upgrade to version 2.6.37-rc3-next-20101125 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.