The ftdi_sio driver (usb/serial/ftdi_sio.c) in Linux kernel 2.6.x up to 2.6.17, and possibly later versions, allows local users to cause a denial of service (memory consumption) by writing more data to the serial port than the hardware can handle, which causes the data to be queued.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://secunia.com/advisories/20703 cve-icon cve-icon
http://secunia.com/advisories/21057 cve-icon cve-icon
http://secunia.com/advisories/21298 cve-icon cve-icon
http://secunia.com/advisories/21605 cve-icon cve-icon
http://secunia.com/advisories/21614 cve-icon cve-icon
http://secunia.com/advisories/21934 cve-icon cve-icon
http://secunia.com/advisories/22093 cve-icon cve-icon
http://secunia.com/advisories/22174 cve-icon cve-icon
http://secunia.com/advisories/24547 cve-icon cve-icon
http://secunia.com/advisories/25226 cve-icon cve-icon
http://secunia.com/advisories/25683 cve-icon cve-icon
http://support.avaya.com/elmodocs2/security/ASA-2006-203.htm cve-icon cve-icon
http://www.debian.org/security/2006/dsa-1184 cve-icon cve-icon
http://www.kernel.org/git/?p=linux/kernel/git/gregkh/patches.git%3Ba=blob%3Bh=4b4d9cfea17618b80d3ac785b701faeaf60141f1%3Bhb=396eb2aac550ec55856c6843ef9017e800c3d656 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2006:150 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2006:151 cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_18_kernel.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_21_kernel.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_30_kernel.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_35_kernel.html cve-icon cve-icon
http://www.osvdb.org/27119 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2006-0617.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/440300/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/19033 cve-icon cve-icon
http://www.ubuntu.com/usn/usn-331-1 cve-icon cve-icon
http://www.ubuntu.com/usn/usn-346-1 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/2841 cve-icon cve-icon
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=197610 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/27807 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2006-2936 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10265 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2006-2936 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T18:06:27.205Z

Reserved: 2006-06-09T00:00:00

Link: CVE-2006-2936

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2006-07-10T19:05:00.000

Modified: 2025-04-03T01:03:51.193

Link: CVE-2006-2936

cve-icon Redhat

Severity : Low

Publid Date: 2006-06-26T00:00:00Z

Links: CVE-2006-2936 - Bugzilla

cve-icon OpenCVE Enrichment

No data.