NetBSD contains a flaw that may allow a local denial of service. The issue is triggered when a malicious user attempts to gather information on a non-existent alias of a network interface via the SIOCGIFALIAS ioctl, resulting in a NULL dereference in the kernel when the alias in question is not located. This will lead to a loss of availability for the platform.
Classification
Location:
Local Access Required
Attack Type:
Denial of Service
Impact:
Loss of Availability
Disclosure:
OSVDB Verified
Solution
Obtain fixed kernel sources, rebuild and install the new kernel, and reboot the system.
The fixed source may be obtained from the NetBSD CVS repository.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.