Two vulnerabilities have been identified in Linux Kernel, which could be exploited by local attackers to cause a denial of service or gain elevated privileges.
The first issue is caused due to certain x86_64 registers not being zero-extended after ptrace in the 32bit entry path, which could be exploited by malicious users to obtain elevated privileges.
The second vulnerability is caused by an error in the ATM module when loaded with CLIP support while the CLIP module is not loaded yet, which could be exploited by malicious users to panic a vulnerable system, creating a denial of service condition.
Credits
Vulnerabilities reported by Wojciech Purczynski and Gilles Espinasse.
ChangeLog
2007-09-24 : Initial release
2007-09-27 : Updated Solution
Vulnerability Management
Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.