Sun announced a security vulnerability affecting their Solaris 10 Operating System this morning. The vulnerability in the acl(2) system call could allow a local user to cause a system panic. The acl(2) system call is used to get or set a file’s access control list. Sun has made a patch available to remedy the problem.

An occurrence of this issue will result in a panic with a stack trace similiar to the following.

unix:panicsys+0x48
unix:vpanic_common+0x78
unix:panic+0x1c
genunix:vmem_xalloc+0x8b0
genunix:vmem_alloc+0x1d4

More detailed information can be found on SunSolve.

#102869: Security Vulnerability Relating to the acl(2) System Call May Allow Denial of Service (DoS) to the System

| More

Related Posts