Linux Kernel Ext3 Invalid Inode Number Denial of Service

Monday, August 07 2006 @ 02:15 PM EDT

Contributed by: sde

James McKenzie has reported a vulnerability in Linux Kernel, which can be exploited by malicious users to cause a DoS (Denial of Service).

The vulnerability is caused due to an error in ext3 when handling an invalid inode number. This can be exploited by sending a specially crafted NFS request with a V2 procedure (e.g. V2_LOOKUP) that specifies an invalid inode number.

Announcement

0 comments



http://www.linuxlinks.com/portal/news/article.php?story=20060807132358410