Mailing the story:

SuSE alert: Linux Kernel

  • Mailing list (Posted by on CST)
  • Story Type: Security; Groups: SUSE
The do_mremap() function of the Linux Kernel is used to manage (move, resize) Virtual Memory Areas (VMAs). By exploiting an incorrect bounds check in do_mremap() during the remapping of memory it is possible to create a VMA with the size of 0. In normal operation do_mremap() leaves a memory hole of one page and creates an additional VMA of two pages. In case of exploitation no hole is created but the new VMA has a 0 bytes length. The Linux Kernel's memory management is corrupted from this point and can be abused by local users to gain root privileges.
What is your name?

What is your E-Mail address?

What is the email address of the recipient?

Add a special note from yourself?