CVE-2011-1083
published 2011-04-04CVE-2011-1083: The epoll implementation in the Linux kernel 2.6.37.2 and earlier does not properly traverse a tree of epoll file descriptors, which allows local users to…
PriorityP419medium4.9CVSS 2.0
AVLACLAuNCNINAC
EXPLOIT
EPSS
0.80%
52.6th percentile
The epoll implementation in the Linux kernel 2.6.37.2 and earlier does not properly traverse a tree of epoll file descriptors, which allows local users to cause a denial of service (CPU consumption) via a crafted application that makes epoll_create and epoll_ctl system calls.
Affected
78 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.23-1 (bookworm) | linux 3.2.23-1 (bookworm) |
| linux | linux_kernel | <= 3.2.23 | — |
| linux | linux_kernel | <= 2.6.37.2 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6f4r-j475-m5hg: The epoll_ctl system call in fs/eventpoll
ghsa_unreviewed·2022-05-17·CVSS 4.9
CVE-2012-3375 [MEDIUM] GHSA-6f4r-j475-m5hg: The epoll_ctl system call in fs/eventpoll
The epoll_ctl system call in fs/eventpoll.c in the Linux kernel before 3.2.24 does not properly handle ELOOP errors in EPOLL_CTL_ADD operations, which allows local users to cause a denial of service (file-descriptor consumption and system crash) via a crafted application that attempts to create a circular epoll dependency. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1083.
GHSA
GHSA-vx34-r39m-w274: The epoll implementation in the Linux kernel 2
ghsa_unreviewed·2022-05-13
CVE-2011-1083 [MEDIUM] CWE-400 GHSA-vx34-r39m-w274: The epoll implementation in the Linux kernel 2
The epoll implementation in the Linux kernel 2.6.37.2 and earlier does not properly traverse a tree of epoll file descriptors, which allows local users to cause a denial of service (CPU consumption) via a crafted application that makes epoll_create and epoll_ctl system calls.
OSV
CVE-2012-3375: The epoll_ctl system call in fs/eventpoll
osv·2012-10-03·CVSS 4.9
CVE-2012-3375 [MEDIUM] CVE-2012-3375: The epoll_ctl system call in fs/eventpoll
The epoll_ctl system call in fs/eventpoll.c in the Linux kernel before 3.2.24 does not properly handle ELOOP errors in EPOLL_CTL_ADD operations, which allows local users to cause a denial of service (file-descriptor consumption and system crash) via a crafted application that attempts to create a circular epoll dependency. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1083.
Red Hat
kernel: epoll: can leak file descriptors when returning -ELOOP
vendor_redhat·2012-03-27·CVSS 4.9
CVE-2012-3375 [MEDIUM] kernel: epoll: can leak file descriptors when returning -ELOOP
kernel: epoll: can leak file descriptors when returning -ELOOP
The epoll_ctl system call in fs/eventpoll.c in the Linux kernel before 3.2.24 does not properly handle ELOOP errors in EPOLL_CTL_ADD operations, which allows local users to cause a denial of service (file-descriptor consumption and system crash) via a crafted application that attempts to create a circular epoll dependency. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1083.
Statement: This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 6, since updates fixing CVE-2011-1083 contained a corrected patch that did not introduce this regression.
This has been addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2012-1061.html, and R
Debian
CVE-2012-3375: linux - The epoll_ctl system call in fs/eventpoll.c in the Linux kernel before 3.2.24 do...
vendor_debian·2012·CVSS 4.9
CVE-2012-3375 [MEDIUM] CVE-2012-3375: linux - The epoll_ctl system call in fs/eventpoll.c in the Linux kernel before 3.2.24 do...
The epoll_ctl system call in fs/eventpoll.c in the Linux kernel before 3.2.24 does not properly handle ELOOP errors in EPOLL_CTL_ADD operations, which allows local users to cause a denial of service (file-descriptor consumption and system crash) via a crafted application that attempts to create a circular epoll dependency. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1083.
Scope: local
bookworm: resolved (fixed in 3.2.23-1)
bullseye: resolved (fixed in 3.2.23-1)
forky: resolved (fixed in 3.2.23-1)
sid: resolved (fixed in 3.2.23-1)
trixie: resolved (fixed in 3.2.23-1)
Red Hat
kernel: excessive in kernel CPU consumption when creating large nested epoll structures
vendor_redhat·2011-02-25·CVSS 4.9
CVE-2011-1083 [MEDIUM] kernel: excessive in kernel CPU consumption when creating large nested epoll structures
kernel: excessive in kernel CPU consumption when creating large nested epoll structures
The epoll implementation in the Linux kernel 2.6.37.2 and earlier does not properly traverse a tree of epoll file descriptors, which allows local users to cause a denial of service (CPU consumption) via a crafted application that makes epoll_create and epoll_ctl system calls.
Statement: This issue affected the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4, 5, 6, and Red Hat Enterprise MRG. It was addressed in Red Hat Enterprise Linux 5 and 6 via RHSA-2012:0150 and RHSA-2012:0862 respectively. There is no plan to address this flaw in Red Hat Enterprise Linux 4. Future updates may address this issue in Red Hat Enterprise MRG.
Package: kernel (Red Hat Enterprise Linux 4) - Will not
No detection rules found.
Bugzilla
CVE-2012-3375 kernel: epoll: can leak file descriptors when returning -ELOOP
bugzilla·2012-07-04·CVSS 4.9
CVE-2012-3375 [MEDIUM] CVE-2012-3375 kernel: epoll: can leak file descriptors when returning -ELOOP
CVE-2012-3375 kernel: epoll: can leak file descriptors when returning -ELOOP
An epoll_ctl(,EPOLL_CTL_ADD,,) operation can return '-ELOOP' to prevent circular epoll dependencies from being created. However, in that case we do not properly clear the 'tfile_check_list'.
An unprivileged local user could use this flaw to crash the system.
This is a regression introduced via the CVE-2011-1083 (bug #681578) fix (commit 28d82dc1c4edbc352129f97f4ca22624d1fe61de):
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=28d82dc1c4edbc352129f97f4ca22624d1fe61de
Upstream fix:
13d518074a952d33d47c428419693f63389547e9
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=13d518074a952d33d47c428419693f63389547e9
References:
https://lkml.org/lkml/2012/
Bugzilla
CVE-2011-1083 kernel: excessive in kernel CPU consumption when creating large nested epoll structures [fedora-all]
bugzilla·2011-10-25·CVSS 4.9
CVE-2011-1083 [MEDIUM] CVE-2011-1083 kernel: excessive in kernel CPU consumption when creating large nested epoll structures [fedora-all]
CVE-2011-1083 kernel: excessive in kernel CPU consumption when creating large nested epoll structures [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=681578
Bugzilla
CVE-2011-1083 kernel: excessive in kernel CPU consumption when creating large nested epoll structures
bugzilla·2011-03-02·CVSS 4.9
CVE-2011-1083 [MEDIUM] CVE-2011-1083 kernel: excessive in kernel CPU consumption when creating large nested epoll structures
CVE-2011-1083 kernel: excessive in kernel CPU consumption when creating large nested epoll structures
Description of problem:
The epoll subsystem allows users to create large nested epoll structures,
which the kernel will then to walk with preemption disabled, causing a denial of
service via excessive CPU consumption in the kernel.
References:
http://thread.gmane.org/gmane.linux.kernel/1105744
http://thread.gmane.org/gmane.linux.kernel/1105744/focus=1105888
http://seclists.org/oss-sec/2011/q1/337
Acknowledgements:
Red Hat would like to thank Nelson Elhage for reporting this issue.
Discussion:
Statement:
This issue affected the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4, 5, 6, and Red Hat Enterprise MRG. It was addressed in Red Hat Enterprise Linux 5 and 6 vi
arXiv
Characteristics, Root Causes, and Detection of Incomplete Security Bug Fixes in the Linux Kernel
arxiv_fulltext·2025-11-21
Characteristics, Root Causes, and Detection of Incomplete Security Bug Fixes in the Linux Kernel
Characteristics, Root Causes, and Detection of
Incomplete Security Bug Fixes in the Linux Kernel
Qiang Liu^1All work was done by Aug., 2022.,
Wenlong Zhang^1,
Muhui Jiang^2,1,
Lei Wu^1,
Yajin Zhou^1
^1Zhejiang University,
^2The Hong Kong Polytechnic University
## Abstract
Security bugs in the Linux kernel emerge endlessly and have attracted much
attention.
However, fixing security bugs in the Linux kernel could be incomplete due to
human mistakes.
Specifically, an incomplete fix fails to repair all the original security
defects in the software, fails to properly repair the original security defects,
or introduces new ones.
In this paper, we study the fixes of incomplete security bugs in the Linux
kernel for the first time, and reveal their characteristics, root causes as well
as de
arXiv
Timeloops: Automatic System Call Policy Learning for Containerized Microservices
arxiv_fulltext·2022-09-26
Timeloops: Automatic System Call Policy Learning for Containerized Microservices
Meghna Pancholi
[email protected]
Columbia University
Andreas D. Kellas
[email protected]
Columbia University
Vasileios P. Kemerlis
[email protected]
Brown University
Simha Sethumadhavan
[email protected]
Columbia University
## Abstract
We introduce , a novel technique for automatically learning system
call filtering policies for containerized microservices applications. At
run-time, automatically learns which system calls a program should
be allowed to invoke, while rejecting attempts to call spurious system calls.
Further, addresses many of the shortcomings of state-of-the-art
static analysis-based techniques, such as the ability to generate tight filters
for programs written in interpreted languages such as PHP, Python, and
JavaScript. has a simple and rob
http://article.gmane.org/gmane.linux.kernel/1105744http://article.gmane.org/gmane.linux.kernel/1105888http://article.gmane.org/gmane.linux.kernel/1106686http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-05/msg00013.htmlhttp://openwall.com/lists/oss-security/2011/03/02/1http://openwall.com/lists/oss-security/2011/03/02/2http://rhn.redhat.com/errata/RHSA-2012-0862.htmlhttp://secunia.com/advisories/43522http://secunia.com/advisories/48115http://secunia.com/advisories/48410http://secunia.com/advisories/48898http://secunia.com/advisories/48964http://www.osvdb.org/71265https://bugzilla.redhat.com/show_bug.cgi?id=681578http://article.gmane.org/gmane.linux.kernel/1105744http://article.gmane.org/gmane.linux.kernel/1105888http://article.gmane.org/gmane.linux.kernel/1106686http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-05/msg00013.htmlhttp://openwall.com/lists/oss-security/2011/03/02/1http://openwall.com/lists/oss-security/2011/03/02/2http://rhn.redhat.com/errata/RHSA-2012-0862.htmlhttp://secunia.com/advisories/43522http://secunia.com/advisories/48115http://secunia.com/advisories/48410http://secunia.com/advisories/48898http://secunia.com/advisories/48964http://www.osvdb.org/71265https://bugzilla.redhat.com/show_bug.cgi?id=681578
2011-04-04
Published