Back to search
CVE-2015-4178
Published: May 2, 2016
Modified: Aug 6, 2024
PUBLISHED
Description
The fs_pin implementation in the Linux kernel before 4.0.5 does not ensure the internal consistency of a certain list data structure, which allows local users to cause a denial of service (system crash) by leveraging user-namespace root access for an MNT_DETACH umount2 system call, related to fs/fs_pin.c and include/linux/fs_pin.h.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20150529 CVE request Linux kernel: ns: user namespaces panic
mailing-list
x_refsource_MLIST
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.0.5
x_refsource_CONFIRM
https://bugzilla.redhat.com/show_bug.cgi?id=1249849
x_refsource_CONFIRM
[oss-security] 20150529 Re: CVE request Linux kernel: ns: user namespaces panic
mailing-list
x_refsource_MLIST
[oss-security] 20150604 Re: Re: CVE request Linux kernel: ns: user namespaces panic
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now