PT-2015-3455 · Linux+2 · Linux Kernel+2
Ben Hutchings
·
Publicado
2015-09-03
·
Atualizado
2021-05-28
·
CVE-2015-7312
CVSS v2.0
4.4
Média
| Vetor | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 3.x and 4.x
Description
The issue is related to multiple race conditions in the Advanced Union Filesystem (aufs) patches for the Linux kernel, specifically in the mm/madvise.c and mm/msync.c components. This can be exploited by local users to cause a denial of service, such as use-after-free and BUG, or possibly gain privileges via system calls like
madvise or msync. The problem arises from concurrent execution with shared resources and improper synchronization.Recommendations
For Linux kernel versions 3.x and 4.x, consider disabling the
madvise and msync system calls as a temporary workaround until a patch is available. Restrict access to the affected components mm/madvise.c and mm/msync.c to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
DoS
Use After Free
Race Condition
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Linux Kernel
Ubuntu