Executive brief
A vulnerability in the file locking service of Red Hat Linux 6.1 and 6.2 allows remote attackers to crash the service. This component is responsible for managing file access between different users and systems; if it fails, applications relying on network file sharing may become unresponsive or unable to access data. This results in a denial of service that can disrupt business operations and server availability.
Technical details
The rpc.lockd daemon in Red Hat Linux 6.1 and 6.2 is vulnerable to a denial of service attack. A remote, unauthenticated attacker can send a specially crafted or malformed RPC request to the lock manager service, causing it to crash or hang. This vulnerability affects the Network Lock Manager (NLM) protocol implementation. Successful exploitation prevents legitimate users and processes from acquiring or releasing file locks on the system, effectively halting network-based file operations. Patches were historically made available by Red Hat to address this issue in the affected versions.
Affected products
- Red Hat Linux 6.1
- Red Hat Linux 6.2
Timeline
- 1994-12-19: disclosed
- 2000-06-20: advisory: Bugtraq disclosure date