kernel: Processes having the same group as `init` can crash kernel
Published Feb 6, 2017
5.5
MEDIUMCVSS 3.0
EPSS 0.43%
Description
include/linux/init_task.h in the Linux kernel before 2.6.35 does not prevent signals with a process group ID of zero from reaching the swapper process, which allows local users to cause a denial of service (system crash) by leveraging access to this process group.
Affected products
No data.
- ≤ 2.6.34.7
No data.
Red Hat Enterprise Linux 5
kernel
Will not fix
Red Hat Enterprise Linux 6
kernel
Will not fix
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise MRG 2
realtime-kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise MRG 2 | realtime-kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw affects Red Hat Enteprise Linux 5 and 6 and is not able to be exploited in the default configuration. Administrators would need to replace the init daemon with alternative systems to exploit this system crash correctly. No update is planned to be released for this flaw.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
AV:L/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.43% (0.00433) | 35.27th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.43% (0.00433) | 34.32th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.07% (0.00072) | 19.39th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00042) | 5.07th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.28% (0.01282) | 68.34th | v2 (v2022.01.01) |
| Feb 22, 2023 | 1.28% (0.01282) | 68.05th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.28% (0.01282) | 65.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.28% (0.01282) | 41.72th | v2 (v2022.01.01) |
References (13)
- http://ftp.naist.jp/pub/linux/kernel/v2.6/ChangeLog-2.6.35 x_refsource_CONFIRMRelease NotesVendor Advisory
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f106eee10038c2ee5b6056aaf3f6d5229be6dcdd x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f20011457f41c11edb5ea5038ad0c8ea9f392023 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=fa2755e20ab0c7215d99c2dc7c262e98a09b01df x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2017/01/21/2 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://www.securityfocus.com/bid/97103 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2010-5328 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1358840 x_refsource_CONFIRMIssue TrackingPatch
- https://github.com/torvalds/linux/commit/f106eee10038c2ee5b6056aaf3f6d5229be6dcdd x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://github.com/torvalds/linux/commit/f20011457f41c11edb5ea5038ad0c8ea9f392023 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://github.com/torvalds/linux/commit/fa2755e20ab0c7215d99c2dc7c262e98a09b01df x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2010-5328
- https://www.cve.org/CVERecord?id=CVE-2010-5328
Change history (0)
No recorded changes yet.