J-Security Center

Title: NetBSD "cpu-hog" Denial of Service Vulnerability

Severity: MODERATE

Description:

In 4.x BSD based unix-variants, code running in the kernel must hand over the CPU voluntarily. If a system call runs for an extended period of time for whatever reason and does not yield the CPU, it is not forced to. Along with this, there are a number of tricks regular users can play to make systemcalls run for a long period of time. As a result, it is possible for malicious users to deny other processes CPU time by consuming all of it and cause a denial of service.

Affected Products:

  • NetBSD NetBSD 1.4.1 Alpha
  • NetBSD NetBSD 1.4.1 SPARC
  • NetBSD NetBSD 1.4.1 arm32
  • NetBSD NetBSD 1.4.1 x86
  • NetBSD NetBSD 1.4.2 Alpha
  • NetBSD NetBSD 1.4.2 SPARC
  • NetBSD NetBSD 1.4.2 arm32
  • NetBSD NetBSD 1.4.2 x86

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.