Solution: Update to version 2.6.19. Vulnerability #1 is also fixed in version 2.6.18.4.
Provided and/or discovered by: 1) Reported by Eugene Teo, further research by a1rsupp1y.
2) Reported by Andi Kleen. Disclosed as a vulnerability via a Red Hat bug report.
3) Originally reported as a kernel bug by Mark Fasheh. Reported as a security issue by Eugene Teo.
4) cagri coltekin.
Changelog: 2008-06-26: Added vulnerability #2 to the advisory. Updated credits and the "Original Advisory" section. Added CVE reference.
2008-10-03: Added vulnerability #3 to the advisory. Updated credits and the "Original Advisory" section. Added CVE reference.
2009-08-24: Updated advisory to include vulnerability #4.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.