thrsleep in kern/kern_synch.c in OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel panic) via a crafted value in the tsp parameter of the __thrsleep system call.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.openbsd.org/errata59.html | release notes |
http://www.openwall.com/lists/oss-security/2016/07/14/5 | third party advisory mailing list |
http://www.openwall.com/lists/oss-security/2016/07/17/7 | mailing list exploit third party advisory |
http://www.openbsd.org/errata58.html | release notes |
http://www.securityfocus.com/bid/91805 | vdb entry |