CVE-2014-3122
MEDIUM severity · CVSS 4.9 · Uncontrolled resource consumption
4.9CVSS MEDIUM
Summary
The try_to_unmap_cluster function in mm/rmap.c in the Linux kernel before 3.14.3 does not properly consider which pages must be locked, which allows local users to cause a denial of service (system crash) by triggering a memory-usage pattern that requires removal of page-table mappings.
Impact & exploitability
Attack vectorLocal
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impactNone
Integrity impactNone
Availability impact—
Exploit probability (EPSS)1%
AV:L/AC:L/Au:N/C:N/I:N/A:C
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.3 ↗
Additional information
- NVD record
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.3Patch
- http://www.openwall.com/lists/oss-security/2014/05/01/7Patch
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=57e68e9cd65b4b8eb4045a1e0d0746458502554c
- http://secunia.com/advisories/59386
- http://secunia.com/advisories/59599
- http://www.debian.org/security/2014/dsa-2926Advisory
- http://www.securityfocus.com/bid/67162Advisory
- http://www.ubuntu.com/usn/USN-2240-1Advisory