MNBSD-2010-1: pseudofs/procfs locking flaw allowing local code execution or system crash

Severity: Unknown

Affected Package: kernel

Summary: pseudofs/procfs locking flaw allowing local code execution or system crash

Description

All pseudofs-based filesystems, including procfs and linprocfs, contained a locking/use-after-free issue in 0.3-PRERELEASE and 0.4-CURRENT that could be exploited by a local user to execute code with kernel privileges or, at minimum, crash the system. Administrators unable to update the kernel were advised to disable proc and linproc mounts. MidnightBSD 0.2.1 was not believed to be affected because the relevant code differed significantly.

Affected Versions

kernel

Recommendations

No specific recommendations provided.

References

Additional Information

Aliases: CVE-2010-4210

Published: October 12, 2010
Last Modified: October 12, 2010