CVE-2012-0879
published 2012-05-17CVE-2012-0879: The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle the CLONE_IO feature, which allows local users to cause a…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.47%
37.9th percentile
The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle the CLONE_IO feature, which allows local users to cause a denial of service (I/O instability) by starting multiple processes that share an I/O context.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| linux | linux_kernel | < 2.6.33 | 2.6.33 |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_high_availability_extension | — | — |
| suse | linux_enterprise_server | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (EC2) vulnerability
vendor_ubuntu·2012-03-27
CVE-2012-0879 Linux kernel (EC2) vulnerability
Title: Linux kernel (EC2) vulnerability
Summary: The system could be made to crash under certain conditions.
Louis Rilling discovered a flaw in Linux kernel's clone command when
CLONE_IO is specified. An unprivileged local user could exploit this to
cause a denial of service.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g.
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2012-03-27
CVE-2012-0879 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash under certain conditions.
Louis Rilling discovered a flaw in Linux kernel's clone command when
CLONE_IO is specified. An unprivileged local user could exploit this to
cause a denial of service.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux
Ubuntu
Linux kernel (FSL-IMX51) vulnerability
vendor_ubuntu·2012-03-27
CVE-2012-0879 Linux kernel (FSL-IMX51) vulnerability
Title: Linux kernel (FSL-IMX51) vulnerability
Summary: The system could be made to crash under certain conditions.
Louis Rilling discovered a flaw in Linux kernel's clone command when
CLONE_IO is specified. An unprivileged local user could exploit this to
cause a denial of service.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages
Red Hat
kernel: block: CLONE_IO io_context refcounting issues
vendor_redhat·2009-12-04·CVSS 5.5
CVE-2012-0879 [MEDIUM] kernel: block: CLONE_IO io_context refcounting issues
kernel: block: CLONE_IO io_context refcounting issues
The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle the CLONE_IO feature, which allows local users to cause a denial of service (I/O instability) by starting multiple processes that share an I/O context.
Statement: This issue affects the Linux kernel as shipped with Red Hat Enterprise Linux 6. This issue does not affect the Linux kernel as shipped with Red Hat Enterprise Linux 4 and 5 as they did not provide support for CLONE_IO. This issue does not affect the Linux kernel as shipped with Red Hat Enterprise MRG as they already contain the fix. This has been addressed in Red Hat Enterprise Linux 6 via https://rhn.redhat.com/errata/RHSA-2012-0481.html.
Package: kernel (Red Hat Enterprise
GHSA
GHSA-7qf4-c29g-g9jg: The I/O implementation for block devices in the Linux kernel before 2
ghsa_unreviewed·2022-05-13
CVE-2012-0879 [MEDIUM] CWE-400 GHSA-7qf4-c29g-g9jg: The I/O implementation for block devices in the Linux kernel before 2
The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle the CLONE_IO feature, which allows local users to cause a denial of service (I/O instability) by starting multiple processes that share an I/O context.
No detection rules found.
No public exploits indexed.
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.33http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=61cc74fbb87af6aa551a06a370590c9bc07e29d9http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b69f2292063d2caf37ca9aec7d63ded203701bf3http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00013.htmlhttp://marc.info/?l=bugtraq&m=139447903326211&w=2http://rhn.redhat.com/errata/RHSA-2012-0481.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0531.htmlhttp://secunia.com/advisories/48545http://secunia.com/advisories/48842http://www.debian.org/security/2012/dsa-2469http://www.openwall.com/lists/oss-security/2012/02/23/5http://www.securitytracker.com/id?1027086http://www.ubuntu.com/usn/USN-1408-1http://www.ubuntu.com/usn/USN-1410-1http://www.ubuntu.com/usn/USN-1411-1https://bugzilla.redhat.com/show_bug.cgi?id=796829https://github.com/torvalds/linux/commit/61cc74fbb87af6aa551a06a370590c9bc07e29d9https://github.com/torvalds/linux/commit/b69f2292063d2caf37ca9aec7d63ded203701bf3http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.33http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=61cc74fbb87af6aa551a06a370590c9bc07e29d9http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b69f2292063d2caf37ca9aec7d63ded203701bf3http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00013.htmlhttp://marc.info/?l=bugtraq&m=139447903326211&w=2http://rhn.redhat.com/errata/RHSA-2012-0481.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0531.htmlhttp://secunia.com/advisories/48545http://secunia.com/advisories/48842http://www.debian.org/security/2012/dsa-2469http://www.openwall.com/lists/oss-security/2012/02/23/5http://www.securitytracker.com/id?1027086http://www.ubuntu.com/usn/USN-1408-1http://www.ubuntu.com/usn/USN-1410-1http://www.ubuntu.com/usn/USN-1411-1https://bugzilla.redhat.com/show_bug.cgi?id=796829https://github.com/torvalds/linux/commit/61cc74fbb87af6aa551a06a370590c9bc07e29d9https://github.com/torvalds/linux/commit/b69f2292063d2caf37ca9aec7d63ded203701bf3
2012-05-17
Published