Vulnerability identifier: #VU99009
Vulnerability risk: Low
CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID:
CWE-ID:
CWE-667
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Linux kernel
Operating systems & Components /
Operating system
Vendor: Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the btrfs_qgroup_inherit() function in fs/btrfs/qgroup.c. A local user can perform a denial of service (DoS) attack.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Linux kernel:
External links
http://git.kernel.org/stable/c/89840b12c8fad7200eb6478525c13261512c01be
http://git.kernel.org/stable/c/3c98e91be6aea4c7acf09da6eb0c107ea9186bb5
http://git.kernel.org/stable/c/f4b930a1602b05e77fee31f9616599b25e910a86
http://git.kernel.org/stable/c/8eb912af525042a7365295eb62f6d5270c2a6462
http://git.kernel.org/stable/c/01d7c41eac9129fba80d8aed0060caab4a7dbe09
http://git.kernel.org/stable/c/044da1a371a0da579e805e89c96865f62d8f6f69
http://git.kernel.org/stable/c/588ae4fdd8b11788a797776b10d6c44ae12bc133
http://git.kernel.org/stable/c/f7e942b5bb35d8e3af54053d19a6bf04143a3955
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.