SB2014101306 - Resource exhaustion in Linux kernel fs
Published: October 13, 2014
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource exhaustion (CVE-ID: CVE-2014-7970)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource exhaustion error within the syscall_define2() function in fs/namespace.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html
- http://secunia.com/advisories/60174
- http://secunia.com/advisories/61142
- http://www.openwall.com/lists/oss-security/2014/10/08/21
- http://www.securityfocus.com/bid/70319
- http://www.securitytracker.com/id/1030991
- http://www.spinics.net/lists/linux-fsdevel/msg79153.html
- http://www.ubuntu.com/usn/USN-2419-1
- http://www.ubuntu.com/usn/USN-2420-1
- http://www.ubuntu.com/usn/USN-2513-1
- http://www.ubuntu.com/usn/USN-2514-1
- https://access.redhat.com/errata/RHSA-2017:1842
- https://access.redhat.com/errata/RHSA-2017:2077
- https://bugzilla.redhat.com/show_bug.cgi?id=1151095
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96921
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0d0826019e529f21c84687521d03f60cd241ca7d