Back

MEDIUM

kernel: Integer overflow in kernel/time/posix-timers.c

Published Jul 2, 2018

Description

An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow in kernel/time/posix-timers.c in the POSIX timer code is caused by the way the overrun accounting works. Depending on interval and expiry time values, the overrun can be larger than INT_MAX, but the accounting is int based. This basically makes the accounting values, which are visible to user space via timer_getoverrun(2) and siginfo::si_overrun, random. For example, a local user can cause a denial of service (signed integer overflow) via crafted mmap, futex, timer_create, and timer_settime system calls.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 2, 2018
Updated Aug 5, 2024
Reserved Jun 26, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date Jun 22, 2018