Integer overflow in the vma_to_resize function in mm/mremap.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (BUG_ON and system crash) via a crafted mremap system call that expands a memory mapping.
Vector
LOCAL
Complexity
LOW
Authentication
NONE
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE
HP IBRIX 6.1.251
HP Hybrid POS Printer with MICR US FK184AA
HP IBRIX 6.1.249
HP IBRIX 6.1.196
HP IBRIX X9320 QP331B
HP IBRIX X9320 QP330B
HP IBRIX 6.1.210
HP IBRIX 6.1.228
HP IBRIX 6.1.243
HP IBRIX 6.1.247
HP IBRIX X9730 QZ731A
HP IBRIX X9300 AW540D
HP HTTP Server 5.93
HP IBRIX X9300 AW539D
HP HTTP Server 5.94
HP IBRIX X9730 QZ730A
HP HTTP Server 5.92