kernel: incorrectly accounted in-flight fds
Published Apr 27, 2016
5.5
MEDIUMCVSS 3.0
EPSS 0.51%
Description
The Linux kernel before 4.5 allows local users to bypass file-descriptor limits and cause a denial of service (memory consumption) by leveraging incorrect tracking of descriptor ownership and sending each descriptor over a UNIX socket before closing it. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-4312.
Affected products
No data.
- ≤ 4.4.8
No data.
Red Hat Enterprise Linux 5
kernel
Will not fix
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise MRG 2
realtime-kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise MRG 2 | realtime-kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/. This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 6, 7 and MRG-2.
References (17)
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=415e3d3e90ce9e18727e8843ae343eda5a58fad6 x_refsource_CONFIRMVendor Advisory
- http://www.debian.org/security/2016/dsa-3503 vendor-advisoryx_refsource_DEBIAN
- http://www.openwall.com/lists/oss-security/2016/02/23/2 mailing-listx_refsource_MLIST
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html x_refsource_CONFIRM
- http://www.ubuntu.com/usn/USN-2946-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2946-2 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2947-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2947-2 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2947-3 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2948-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2948-2 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2949-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2016-2550 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1311517 x_refsource_CONFIRMIssue Tracking
- https://github.com/torvalds/linux/commit/415e3d3e90ce9e18727e8843ae343eda5a58fad6 x_refsource_CONFIRMPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-2550
- https://www.cve.org/CVERecord?id=CVE-2016-2550
Change history (0)
No recorded changes yet.