Back to search
CVE-2015-4177
Published: May 2, 2016
Modified: Aug 6, 2024
PUBLISHED
Description
The collect_mounts function in fs/namespace.c in the Linux kernel before 4.0.5 does not properly consider that it may execute after a path has been unmounted, which allows local users to cause a denial of service (system crash) by leveraging user-namespace root access for an MNT_DETACH umount2 system call.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20150529 CVE request Linux kernel: ns: user namespaces panic
mailing-list
x_refsource_MLIST
https://bugzilla.redhat.com/show_bug.cgi?id=1248486
x_refsource_CONFIRM
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.0.5
x_refsource_CONFIRM
[oss-security] 20150529 Re: CVE request Linux kernel: ns: user namespaces panic
mailing-list
x_refsource_MLIST
[oss-security] 20150604 Re: Re: CVE request Linux kernel: ns: user namespaces panic
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now