Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-1146
HistoryMar 07, 2012 - 12:00 a.m.

CVE-2012-1146

2012-03-0700:00:00
ubuntu.com
ubuntu.com
12

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0

Percentile

9.8%

The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the
Linux kernel before 3.2.10 does not properly handle multiple events that
are attached to the same eventfd, which allows local users to cause a
denial of service (NULL pointer dereference and system crash) or possibly
have unspecified other impact by registering memory threshold events.

Bugs

Notes

Author Note
mdeslaur Upstream commit: 371528c (3.3-rc5)
apw this functionality appears in the commit below, added break-fix: 2e72b6347c9459e6cff5634ddc815485bae6985f

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0

Percentile

9.8%