Vulnerability identifier: #VU103921
Vulnerability risk: Low
CVSSv4.0: 1.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:U/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-399
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Linux kernel
Operating systems & Components /
Operating system
Vendor: Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the hrtimers_prepare_cpu() and hrtimers_cpu_dying() functions in kernel/time/hrtimer.c. A local user can perform a denial of service (DoS) attack.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Linux kernel: All versions
External links
https://git.kernel.org/stable/c/14984139f1f2768883332965db566ef26db609e7
https://git.kernel.org/stable/c/15b453db41d36184cf0ccc21e7df624014ab6a1a
https://git.kernel.org/stable/c/2f8dea1692eef2b7ba6a256246ed82c365fdc686
https://git.kernel.org/stable/c/38492f6ee883c7b1d33338bf531a62cff69b4b28
https://git.kernel.org/stable/c/3d41dbf82e10c44e53ea602398ab002baec27e75
https://git.kernel.org/stable/c/95e4f62df23f4df1ce6ef897d44b8e23c260921a
https://git.kernel.org/stable/c/a5cbbea145b400e40540c34816d16d36e0374fbc
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.