CVE-2012-1146

Severity
5.5MEDIUM
EPSS
0.1%
top 73.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 17
Latest updateMay 13

Description

The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 does not properly handle multiple events that are attached to the same eventfd, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by registering memory threshold events.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages18 packages

NVDlinux/linux_kernel< 3.2.10
Ubuntulinux< 3.11.0-12.19+1
Ubuntulinux-aws< 4.4.0-1002.2+1
Ubuntulinux-flo< 3.4.0-1.3+1
Ubuntulinux-gke< 4.4.0-1003.3

Also affects: Fedora 16

Patches

🔴Vulnerability Details

3
GHSA
GHSA-83vv-q4vw-p24m: The mem_cgroup_usage_unregister_event function in mm/memcontrol2022-05-13
CVEList
CVE-2012-1146: The mem_cgroup_usage_unregister_event function in mm/memcontrol2012-05-17
OSV
CVE-2012-1146: The mem_cgroup_usage_unregister_event function in mm/memcontrol2012-03-07

📋Vendor Advisories

8
Ubuntu
Linux kernel (OMAP4) vulnerabilities2012-05-31
Ubuntu
Linux kernel (OMAP4) vulnerabilities2012-05-18
Ubuntu
Linux kernel (Natty backport) vulnerabilities2012-05-08
Ubuntu
Linux kernel vulnerabilities2012-05-01
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities2012-05-01

💬Community

2
Bugzilla
CVE-2012-1146 kernel: mm: memcg: unregistring of events attached to the same eventfd can lead to oops [fedora-all]2012-03-07
Bugzilla
CVE-2012-1146 kernel: mm: memcg: unregistring of events attached to the same eventfd can lead to oops2012-03-07
CVE-2012-1146 (MEDIUM CVSS 5.5) | The mem_cgroup_usage_unregister_eve | cvebase.io