Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.
Race condition in the page fault handler (fault.c) for Linux kernel 2.2.x to 2.2.7 2.4 to 2.4.29 and 2.6 to 2.6.10 when running on multiprocessor machines allows local users to execute arbitrary code via concurrent threads that share the same virtual memory space and simultaneously request stack expansion.
- Oracle Linux 4
- CentOS Linux 4
- Red Hat Enterprise Linux 4