Double free vulnerability in the utrace support in the Linux kernel, probably 2.6.18, in Red Hat Enterprise Linux (RHEL) 5 and Fedora Core 6 (FC6) allows local users to cause a denial of service (oops), as demonstrated by a crash when running the GNU GDB testsuite, a different vulnerability than CVE-2008-2365.
The product calls free() twice on the same memory address.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/43556 | third party advisory vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=449359 | vendor advisory issue tracking exploit |
https://bugzilla.redhat.com/show_bug.cgi?id=207002 | vendor advisory issue tracking |