CVE-2012-0879

Severity
5.5MEDIUM
EPSS
0.0%
top 86.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 17
Latest updateMay 13

Description

The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle the CLONE_IO feature, which allows local users to cause a denial of service (I/O instability) by starting multiple processes that share an I/O context.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

Also affects: Debian Linux 6.0, Ubuntu Linux 10.04

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7qf4-c29g-g9jg: The I/O implementation for block devices in the Linux kernel before 22022-05-13
CVEList
CVE-2012-0879: The I/O implementation for block devices in the Linux kernel before 22012-05-17

📋Vendor Advisories

4
Ubuntu
Linux kernel (EC2) vulnerability2012-03-27
Ubuntu
Linux kernel vulnerability2012-03-27
Ubuntu
Linux kernel (FSL-IMX51) vulnerability2012-03-27
Red Hat
kernel: block: CLONE_IO io_context refcounting issues2009-12-04

💬Community

1
Bugzilla
CVE-2012-0879 kernel: block: CLONE_IO io_context refcounting issues2012-02-23
CVE-2012-0879 (MEDIUM CVSS 5.5) | The I/O implementation for block de | cvebase.io