Back to search
CVE-2008-1294
Published: May 2, 2008
Modified: Aug 7, 2024
PUBLISHED
Description
Linux kernel 2.6.17, and other versions before 2.6.22, does not check when a user attempts to set RLIMIT_CPU to 0 until after the change is made, which allows local users to bypass intended resource limits.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://bugs.gentoo.org/show_bug.cgi?id=215000
x_refsource_CONFIRM
USN-618-1
vendor-advisory
x_refsource_UBUNTU
31341
third-party-advisory
x_refsource_SECUNIA
DSA-1565
vendor-advisory
x_refsource_DEBIAN
oval:org.mitre.oval:def:10974
vdb-entry
signature
x_refsource_OVAL
29004
vdb-entry
x_refsource_BID
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22
x_refsource_CONFIRM
RHSA-2008:0612
vendor-advisory
x_refsource_REDHAT
30769
third-party-advisory
x_refsource_SECUNIA
30018
third-party-advisory
x_refsource_SECUNIA
linux-kernel-rlimitcpu-security-bypass(42145)
vdb-entry
x_refsource_XF
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now