Vulnerability identifier: #VU91363
Vulnerability risk: Low
CVSSv3.1: 4.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID:
CWE-ID:
CWE-200
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Linux kernel
Operating systems & Components /
Operating system
Vendor: Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to information disclosure within the do_sys_name_to_handle() function in fs/fhandle.c. A local user can perform a denial of service (DoS) attack.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Linux kernel:
External links
http://git.kernel.org/stable/c/4bac28f441e3cc9d3f1a84c8d023228a68d8a7c1
http://git.kernel.org/stable/c/772a7def9868091da3bcb0d6c6ff9f0c03d7fa8b
http://git.kernel.org/stable/c/cde76b3af247f615447bcfecf610bb76c3529126
http://git.kernel.org/stable/c/423b6bdf19bbc5e1f7e7461045099917378f7e71
http://git.kernel.org/stable/c/e6450d5e46a737a008b4885aa223486113bf0ad6
http://git.kernel.org/stable/c/c1362eae861db28b1608b9dc23e49634fe87b63b
http://git.kernel.org/stable/c/cba138f1ef37ec6f961baeab62f312dedc7cf730
http://git.kernel.org/stable/c/bf9ec1b24ab4e94345aa1c60811dd329f069c38b
http://git.kernel.org/stable/c/3948abaa4e2be938ccdfc289385a27342fb13d43
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.