PT-2015-3455 · Linux+2 · Linux Kernel+2
Ben Hutchings
·
Published
2015-09-03
·
Updated
2021-05-28
·
CVE-2015-7312
CVSS v2.0
4.4
Medium
| Vector | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 3.x and 4.x
Description
The issue is related to multiple race conditions in the Advanced Union Filesystem (aufs) patches for the Linux kernel, specifically in the mm/madvise.c and mm/msync.c components. This can be exploited by local users to cause a denial of service, such as use-after-free and BUG, or possibly gain privileges via system calls like
madvise or msync. The problem arises from concurrent execution with shared resources and improper synchronization.Recommendations
For Linux kernel versions 3.x and 4.x, consider disabling the
madvise and msync system calls as a temporary workaround until a patch is available. Restrict access to the affected components mm/madvise.c and mm/msync.c to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
DoS
Use After Free
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Linux Kernel
Ubuntu