Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j4w8-rj66-g2q9

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.7

Описание

An issue was discovered in the Linux kernel 4.18 through 5.6.11 when unprivileged user namespaces are allowed. A user can create their own PID namespace, and mount a FUSE filesystem. Upon interaction with this FUSE filesystem, if the userspace component is terminated via a kill of the PID namespace's pid 1, it will result in a hung task, and resources being permanently locked up until system reboot. This can result in resource exhaustion.

An issue was discovered in the Linux kernel 4.18 through 5.6.11 when unprivileged user namespaces are allowed. A user can create their own PID namespace, and mount a FUSE filesystem. Upon interaction with this FUSE filesystem, if the userspace component is terminated via a kill of the PID namespace's pid 1, it will result in a hung task, and resources being permanently locked up until system reboot. This can result in resource exhaustion.

EPSS

Процентиль: 26%
0.00093
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-400
CWE-772

Связанные уязвимости

CVSS3: 4.7
ubuntu
больше 5 лет назад

An issue was discovered in the Linux kernel 4.18 through 5.6.11 when unprivileged user namespaces are allowed. A user can create their own PID namespace, and mount a FUSE filesystem. Upon interaction with this FUSE filesystem, if the userspace component is terminated via a kill of the PID namespace's pid 1, it will result in a hung task, and resources being permanently locked up until system reboot. This can result in resource exhaustion.

CVSS3: 4.7
redhat
больше 5 лет назад

An issue was discovered in the Linux kernel 4.18 through 5.6.11 when unprivileged user namespaces are allowed. A user can create their own PID namespace, and mount a FUSE filesystem. Upon interaction with this FUSE filesystem, if the userspace component is terminated via a kill of the PID namespace's pid 1, it will result in a hung task, and resources being permanently locked up until system reboot. This can result in resource exhaustion.

CVSS3: 4.7
nvd
больше 5 лет назад

An issue was discovered in the Linux kernel 4.18 through 5.6.11 when unprivileged user namespaces are allowed. A user can create their own PID namespace, and mount a FUSE filesystem. Upon interaction with this FUSE filesystem, if the userspace component is terminated via a kill of the PID namespace's pid 1, it will result in a hung task, and resources being permanently locked up until system reboot. This can result in resource exhaustion.

CVSS3: 4.7
msrc
больше 5 лет назад

Описание отсутствует

CVSS3: 4.7
debian
больше 5 лет назад

An issue was discovered in the Linux kernel 4.18 through 5.6.11 when u ...

EPSS

Процентиль: 26%
0.00093
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-400
CWE-772