
Find real vulnerabilities before they ship
The asynchronous I/O facility in 4.4 BSD kernel does not check user credentials when setting the recipient of I/O notification, which allows local users to cause a denial of service by using certain ioctl and fcntl calls to cause the signal to be sent to an arbitrary process ID.
| Base Score | 2.1 |
|---|---|
| Vector String | AV:L/AC:L/Au:N/C:N/I:N/A:P |
| Base Severity | Unknown |
| Version | 2.0 |
| Attack Vector (AV) |