ELSA-2015-0783 -- Oracle kernel_oracleasm_ocfs2ID: oval:org.secpod.oval:def:1500979 | Date: (C)2015-04-13 (M)2024-06-13 |
Class: PATCH | Family: unix |
The InfiniBand (IB) implementation in the Linux kernel package does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device under /dev/infiniband/.
Product: |
kernel |
oracleasm |
ocfs2 |