The Linux kernel 2.6.24 and 2.6.25 before 2.6.25.9 allows local users to cause a denial of service (memory consumption) via a large number of calls to the get_user_pages function, which lacks a ZERO_PAGE optimization and results in allocation of "useless newly zeroed pages."
2008-07-02T16:41:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 4.9 (MEDIUM)
AV:L/AC:L/Au:N/C:N/I:N/A:C
3.9
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | 2.6.24 | Yes |
Operating System | linux | linux_kernel | 2.6.25 | Yes |
Operating System | linux | linux_kernel | 2.6.25.1 | Yes |
Operating System | linux | linux_kernel | 2.6.25.2 | Yes |
Operating System | linux | linux_kernel | 2.6.25.3 | Yes |
Operating System | linux | linux_kernel | 2.6.25.4 | Yes |
Operating System | linux | linux_kernel | 2.6.25.5 | Yes |
Operating System | linux | linux_kernel | 2.6.25.6 | Yes |
Operating System | linux | linux_kernel | 2.6.25.7 | Yes |
Operating System | linux | linux_kernel | 2.6.25.8 | Yes |