fs/pipe.c in the Linux kernel prior to 4.5 does not limit the amount of unread data in pipes, which allows local users to cause a denial of service (memory consumption) by creating many pipes with non-default sizes.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
linux linux kernel |
||
novell suse linux enterprise module for public cloud 12.0 |
||
novell suse linux enterprise server 11.0 |
||
novell suse linux enterprise server 12.0 |
||
novell suse linux enterprise live patching 12.0 |
||
novell suse linux enterprise real time extension 11.0 |
||
novell suse linux enterprise desktop 12.0 |
||
novell suse linux enterprise real time extension 12.0 |
||
novell suse linux enterprise workstation extension 12.0 |
||
novell suse linux enterprise debuginfo 11.0 |
||
novell suse linux enterprise software development kit 11.0 |
||
novell suse linux enterprise software development kit 12.0 |
This is kind of a big deal because the mess is in 14.04 LTS, expiry date 2019
Ubuntu has patched four Linux kernel vulnerabilities that allowed for arbitrary code execution and denial of service attacjs. The flaws (CVE-2015-8812, CVE-2016-2085, CVE-2016-2550, CVE-2016-2847) is fixed in Ubuntu 14.04 LTS. Researcher Venkatesh Pottem found a use-after-free vulnerability in the Linux kernel CXGB3 driver which local hackers could use to trigger a crash or execute arbitrary code. Xiaofei Rex Guo reported a second timing side channel vulnerability in the Linux Extended Verificat...