CVE-2007-4130Improper Input Validation in Redhat Enterprise Linux

Severity
7.2HIGHNVD
EPSS
0.0%
top 86.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 5
Latest updateMay 1

Description

The Linux kernel 2.6.9 before 2.6.9-67 in Red Hat Enterprise Linux (RHEL) 4 on Itanium (ia64) does not properly handle page faults during NUMA memory access, which allows local users to cause a denial of service (panic) via invalid arguments to set_mempolicy in an MPOL_BIND operation.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages1 packages

Also affects: Enterprise Linux 4.0

Patches

🔴Vulnerability Details

1
GHSA
GHSA-w57x-j39p-mpp8: The Linux kernel 22022-05-01

📋Vendor Advisories

1
Red Hat
panic caused by set_mempolicy with MPOL_BIND2006-02-01

💬Community

1
Bugzilla
CVE-2007-4130 panic caused by set_mempolicy with MPOL_BIND2006-02-01