Junglewise Threat Intelligence

CVE-2000-0508: Red Hat Linux rpc.lockd denial of service via malformed request

CVE-2000-0508 · Severity: medium · CVSS 5 · Published 1994-12-19

Vendors: Red Hat.

Executive brief

A vulnerability in the file locking service of Red Hat Linux 6.1 and 6.2 allows remote attackers to crash the service. This component is responsible for managing file access between different users and systems; if it fails, applications relying on network file sharing may become unresponsive or unable to access data. This results in a denial of service that can disrupt business operations and server availability.

Technical details

The rpc.lockd daemon in Red Hat Linux 6.1 and 6.2 is vulnerable to a denial of service attack. A remote, unauthenticated attacker can send a specially crafted or malformed RPC request to the lock manager service, causing it to crash or hang. This vulnerability affects the Network Lock Manager (NLM) protocol implementation. Successful exploitation prevents legitimate users and processes from acquiring or releasing file locks on the system, effectively halting network-based file operations. Patches were historically made available by Red Hat to address this issue in the affected versions.

Affected products

  • Red Hat Linux 6.1
  • Red Hat Linux 6.2

Timeline

  • 1994-12-19: disclosed
  • 2000-06-20: advisory: Bugtraq disclosure date

References