Security Vulnerability in x64 Kernel Processing may Cause a System Panic



Category :Security
Release Phase :Resolved
Product :Solaris 10 Operating System  
Bug Id :6247143  
Date of Resolved Release :31-JAN-2006 


Impact

A security vulnerability in Solaris 10 x64 kernel processing may allow a local unprivileged user the ability to cause a system panic, creating a Denial of Service (DoS) condition.


Contributing Factors

This issue can occur in the following release:

x86 Platform

  • Solaris 10 without patch 118844-14

Note: This issue only affects x64 platforms when running in 64-bit mode. SPARC and 32-bit x86 platforms are not affected. Solaris 8 and Solaris 9 do not have support for the x64 architecture and thus are not affected by this issue.

To determine if a system is running in 64-bit mode, the following command can be run:

    $ isainfo -b
    64

If "64" is returned, the system is running in 64-bit mode.


Symptoms

If the described issue occurs, the system will panic and a message similar to the following will be seen on the console:

    panic[cpu3]/thread=ffffffff8e6ab880: bad_set_user_regs: rp=fffffe8008708f10 rp->r_cs=0;

Workaround

To workaround the described issue, boot the system in 32-bit mode.

To specify the 32-bit kernel, as root or with equivalent privileges, enter the following command:

    # eeprom boot-file=kernel/unix

Upon the next reboot, the system will be running the 32-bit kernel.

Once the patch for this issue is installed, to reinstate 64 bit mode, as root or with equivalent privileges, enter the following command:

    # eeprom boot-file=kernel/amd64/unix

Upon the next reboot, the system will be running the 64-bit kernel.


Resolution

This issue is addressed in the following release:

x86 Platform

  • Solaris 10 with patch 118844-14 or later





Attachments
This solution has no attachment

 
 
Login Required

You must login and have a valid contract to access Sun's Premium content which includes:

  • Sun Alerts
  • Bugs
  • Patches
  • Solutions
  • White Papers
  • Documentation
  • Support Knowledge

Login Required

You must login and have a valid contract to access Sun's contracted features

Access Legend:

(Login to access)   Sun Contracted Content
(Login to access)   Sun Contracted Feature

Please make use of SunSolve Feedback application by selecting the floating [+] to provide feedback about this specific document.

Search

Article Details
Article ID : 200460
Article Type : Sun Alert
Last reviewed : 2006-11-07
Audience : PUBLIC
Keywords :
Provide feedback  (help)
Page Tools
»  Print This Page
»  Email This Article
»  Bookmark This Article