The mmap extension __MAP_NOFAULT in OpenBSD 5.8 and 5.9 allows attackers to cause a denial of service (kernel panic and crash) via a large size value.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1036318 | vdb entry |
http://www.openbsd.org/errata59.html | release notes |
http://www.openwall.com/lists/oss-security/2016/07/14/5 | third party advisory mailing list |
http://www.openwall.com/lists/oss-security/2016/07/17/7 | mailing list third party advisory exploit |
http://www.openbsd.org/errata58.html | release notes |
http://www.securityfocus.com/bid/91805 | vdb entry |