Description: A vulnerability and a weakness have been reported in Linux Kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
1) An error exists when the kernel returns program control using SYSRET on Intel EM64T CPUs. The may cause a DoS due to the way Intel EM64T CPUs handle uncanonical return addresses when a user has been able to change the frames.
2) Improperly use of BUG_ON in the "__group_complete_signal()" function may in certain cases be exploited to cause unwanted process crashes.
Solution: Update to version 2.6.16.5.
Provided and/or discovered by: 1) Reported by the vendor.
2) Oleg Nesterov
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.