When running a binary with a lot of shared libraries, predictable base address is used for one of the loaded libraries. This flaw could be used to bypass ASLR. References: http://scarybeastsecurity.blogspot.com/2012/03/some-random-observations-on-linux-aslr.html
Created kernel tracking bugs for this issue Affects: fedora-all [bug 804957]
kernel-3.3.0-4.fc16 has been pushed to the Fedora 16 stable repository. If problems still persist, please make note of it in this bug report.
kernel-2.6.42.12-1.fc15 has been pushed to the Fedora 15 stable repository. If problems still persist, please make note of it in this bug report.
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2012:1426 https://rhn.redhat.com/errata/RHSA-2012-1426.html
Statement: (none)
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2013:0168 https://rhn.redhat.com/errata/RHSA-2013-0168.html