DescriptionThe int3 handler in the Linux kernel before 3.3 relies on a per-CPU debug stack, which allows local users to cause a denial of service (stack corruption and panic) via a crafted application that triggers certain lock contention.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs672660

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linux-2.6sourcesqueeze(not affected)


[squeeze] - linux-2.6 <not-affected> (rt patchset not yet present)
Ben Hutchings said it was fixed in 3.2.9-1, I checked it for 3.2.16-1

Search for package or bug name: Reporting problems