UBUNTU-CVE-2016-2550
The Linux kernel before 4.5 allows local users to bypass file-descriptor limits and cause a denial of service (memory consumption) by leveraging incorrect tracking of descriptor ownership and sending each descriptor over a UNIX socket before closing it. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-4312.
02 / AFFECTED SOFTWARE
Affected packages
87 explicit affected versions
38 explicit affected versions
23 explicit affected versions
10 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The Linux kernel before 4.5 allows local users to bypass file-descriptor limits and cause a denial of service (memory consumption) by leveraging incorrect tracking of descriptor ownership and sending each descriptor over a UNIX socket before closing it. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-4312.
05 / REFERENCES
Further evidence
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=415e3d3e90ce9e18727e8843ae343eda5a58fad6
- http://www.openwall.com/lists/oss-security/2016/02/24/2
- https://ubuntu.com/security/CVE-2016-2550
- https://ubuntu.com/security/notices/USN-2946-1
- https://ubuntu.com/security/notices/USN-2946-2
- https://ubuntu.com/security/notices/USN-2947-1
- https://ubuntu.com/security/notices/USN-2947-2
- https://ubuntu.com/security/notices/USN-2947-3
- https://ubuntu.com/security/notices/USN-2948-1
- https://ubuntu.com/security/notices/USN-2949-1
- https://www.cve.org/CVERecord?id=CVE-2016-2550