PT-2012-3098 · Linux+1 · Linux Kernel+1

Petr Matousek

·

Published

2012-03-07

·

Updated

2023-02-13

·

CVE-2012-1146

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.2.10
Description The issue is related to the mem cgroup usage unregister event function in mm/memcontrol.c, which does not properly handle multiple events attached to the same eventfd. This can be exploited by local users to cause a denial of service, resulting in a NULL pointer dereference and system crash, or possibly have other unspecified impacts by registering memory threshold events.
Recommendations For Linux kernel versions prior to 3.2.10, update to version 3.2.10 or later to resolve the issue.

Exploit

Fix

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2012-1146
USN-1260-1
USN-1405-1
USN-1406-1
USN-1407-1
USN-1421-1
USN-1422-1
USN-1431-1
USN-1433-1
USN-1440-1
USN-1446-1
USN-1458-1

Affected Products

Linux Kernel
Suse