CVE: CAN-2004-0427 Updated: Tue, 06 Jul 2004 13:45:36 +0900 Summary: The do_fork function in Linux 2.4.x and 2.6.x does not properly decrement the mm_count counter when an error occurs after the mm_struct for a child process has been activated, which triggers a memory leak that allows local users to cause a denial of service (memory exhaustion). (text:CAN-2004-0427) Priority: Low Status: Closed Source: SuSE-SA:2004:010, FEDORA-2004-111, RHSA-2004:255-10 Link: http://www.ultramonkey.org/news_archive.shtml#2004062601 Resolved In: Kernel: 2.4.26-rc4 Patch: http://linux.bkbits.net:8080/linux-2.4/cset@1.1356 Red Hat Linux 7.3: Vendor: None (EOL) UltraMonkey: kernel-2.4.20-31.9.um.1 Red Hat Linux 8.0: Vendor: None (EOL) UltraMonkey: kernel-2.4.20-31.9.um.1 Red Hat Linux 9: Vendor: None (EOL) UltraMonkey: kernel-2.4.20-31.9.um.1 Fedora Core 1: Vendor: kernel-2.4.22-1.2188.nptl UltraMonkey: kernel-2.4.22-1.2194.nptl.um.1 Red Hat Enterprise Linux 3: Vendor: kernel-2.4.21-15.0.2.EL UltraMonkey: kernel-2.4.21-15.0.2.EL.um.1 Debian Woody: Vendor: None UltraMonkey: kernel-source-2.4.22-1-ipvs_2.4.22-7woody.um.4 Debian Sid: Vendor: kernel-source-2.4.26_2.4.26-1 UltraMonkey: kernel-source-2.4.22-1-ipvs_2.4.22-7.um.4