Back to search
CVE-2012-3375
Published: Oct 3, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
The epoll_ctl system call in fs/eventpoll.c in the Linux kernel before 3.2.24 does not properly handle ELOOP errors in EPOLL_CTL_ADD operations, which allows local users to cause a denial of service (file-descriptor consumption and system crash) via a crafted application that attempts to create a circular epoll dependency. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1083.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://downloads.avaya.com/css/P8/documents/100165733
x_refsource_CONFIRM
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.24
x_refsource_CONFIRM
1027237
vdb-entry
x_refsource_SECTRACK
51164
third-party-advisory
x_refsource_SECUNIA
[oss-security] 20120704 Re: CVE Request -- kernel: epoll: can leak file descriptors when returning -ELOOP
mailing-list
x_refsource_MLIST
USN-1529-1
vendor-advisory
x_refsource_UBUNTU
https://bugzilla.redhat.com/show_bug.cgi?id=837502
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now