UBUNTU-CVE-2016-6213
Dashboard / Vulnerabilities / UBUNTU-CVE-2016-6213
UBUNTU-CVE-2016-6213
Summary:
Details: fs/namespace.c in the Linux kernel before 4.9 does not restrict how many mounts may exist in a mount namespace, which allows local users to cause a denial of service (memory consumption and deadlock) via MS_BIND mount system calls, as demonstrated by a loop that triggers exponential growth in the number of mounts.
References: https://ubuntu.com/security/CVE-2016-6213, http://www.openwall.com/lists/oss-security/2016/07/13/6, https://ubuntu.com/security/notices/USN-3160-1, https://ubuntu.com/security/notices/USN-3160-2, https://ubuntu.com/security/notices/USN-3161-1, https://ubuntu.com/security/notices/USN-3161-2, https://ubuntu.com/security/notices/USN-3161-3, https://ubuntu.com/security/notices/USN-3161-4, https://ubuntu.com/security/notices/USN-3162-1, https://ubuntu.com/security/notices/USN-3162-2, https://www.cve.org/CVERecord?id=CVE-2016-6213
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
