Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SystemTap 1.4, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero error and OOPS) via a crafted ELF program with DWARF expressions that are not properly handled by a stap script that performs stack unwinding (aka backtracing).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SystemTap 'translate()'函数零除错误拒绝服务漏洞
Vulnerability Description
SystemTap是一套Linux内核诊断工具。该工具允许从运行的Linux内核快速和安全的获取信息。 当无特权(又称stapusr)模式启用时,SystemTap 1.4版本中存在拒绝服务漏洞。loc2c.c的“translate()”函数中存在的零除错误导致产生此漏洞,本地用户可借助带有DWARF表达式的特制ELF程序导致拒绝服务(零除错误和OOPS),该表达式没有被执行栈回溯的stap脚本正确处理。
CVSS Information
N/A
Vulnerability Type
N/A