CVE-2012-1146
published 2012-05-17CVE-2012-1146: The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 does not properly handle multiple events that are attached…
PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.52%
40.7th percentile
The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 does not properly handle multiple events that are attached to the same eventfd, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by registering memory threshold events.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| linux | linux_kernel | < 3.2.10 | 3.2.10 |
| linux | linux_kernel | >= 0 < 3.11.0-12.19 | 3.11.0-12.19 |
| linux | linux_kernel | >= 0 < 4.2.0-16.19 | 4.2.0-16.19 |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_high_availability_extension | — | — |
| suse | linux_enterprise_server | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-05-31·CVSS 4.9
CVE-2011-4086 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was found in the Linux's kernels ext4 file system when mounted with
a journal. A local, unprivileged user could exploit this flaw to cause a
denial of service. (CVE-2011-4086)
A flaw was discovered in the Linux kernel's cifs file system. An
unprivileged local user could exploit this flaw to crash the system leading
to a denial of service. (CVE-2012-1090)
H. Peter Anvin reported a flaw in the Linux kernel that could crash the
system. A local user could exploit this flaw to crash the system.
(CVE-2012-1097)
A flaw was discovered in the Linux kernel's cgroups subset. A local
attacker could use this flaw to crash the system. (CVE-2012-1146)
A flaw was found in the Linux kernel's
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-05-18·CVSS 4.9
CVE-2011-4086 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was found in the Linux's kernels ext4 file system when mounted with
a journal. A local, unprivileged user could exploit this flaw to cause a
denial of service. (CVE-2011-4086)
A flaw was discovered in the Linux kernel's cifs file system. An
unprivileged local user could exploit this flaw to crash the system leading
to a denial of service. (CVE-2012-1090)
H. Peter Anvin reported a flaw in the Linux kernel that could crash the
system. A local user could exploit this flaw to crash the system.
(CVE-2012-1097)
A flaw was discovered in the Linux kernel's cgroups subset. A local
attacker could use this flaw to crash the system. (CVE-2012-1146)
A flaw was found in the Linux kernel's
Ubuntu
Linux kernel (Natty backport) vulnerabilities
vendor_ubuntu·2012-05-08·CVSS 4.9
CVE-2011-4086 [MEDIUM] Linux kernel (Natty backport) vulnerabilities
Title: Linux kernel (Natty backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was found in the Linux's kernels ext4 file system when mounted with
a journal. A local, unprivileged user could exploit this flaw to cause a
denial of service. (CVE-2011-4086)
Sasha Levin discovered a flaw in the permission checking for device
assignments requested via the kvm ioctl in the Linux kernel. A local user
could use this flaw to crash the system causing a denial of service.
(CVE-2011-4347)
Stephan Bärwolf discovered a flaw in the KVM (kernel-based virtual
machine) subsystem of the Linux kernel. A local unprivileged user can crash
use this flaw to crash VMs causing a deny of service. (CVE-2012-0045)
A flaw was discovered in the Linux kernel's cifs file system
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-05-01·CVSS 4.9
CVE-2012-4398 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was found in the Linux's kernels ext4 file system when mounted with
a journal. A local, unprivileged user could exploit this flaw to cause a
denial of service. (CVE-2011-4086)
Sasha Levin discovered a flaw in the permission checking for device
assignments requested via the kvm ioctl in the Linux kernel. A local user
could use this flaw to crash the system causing a denial of service.
(CVE-2011-4347)
Stephan Bärwolf discovered a flaw in the KVM (kernel-based virtual
machine) subsystem of the Linux kernel. A local unprivileged user can crash
use this flaw to crash VMs causing a deny of service. (CVE-2012-0045)
A flaw was discovered in the Linux kernel's cifs file system. An
unprivileged
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities
vendor_ubuntu·2012-05-01·CVSS 4.9
CVE-2011-4086 [MEDIUM] Linux kernel (Oneiric backport) vulnerabilities
Title: Linux kernel (Oneiric backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was found in the Linux's kernels ext4 file system when mounted with
a journal. A local, unprivileged user could exploit this flaw to cause a
denial of service. (CVE-2011-4086)
Sasha Levin discovered a flaw in the permission checking for device
assignments requested via the kvm ioctl in the Linux kernel. A local user
could use this flaw to crash the system causing a denial of service.
(CVE-2011-4347)
Stephan Bärwolf discovered a flaw in the KVM (kernel-based virtual
machine) subsystem of the Linux kernel. A local unprivileged user can crash
use this flaw to crash VMs causing a deny of service. (CVE-2012-0045)
A flaw was discovered in the Linux kernel's cifs file syst
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-04-12·CVSS 4.0
CVE-2012-1097 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Sasha Levin discovered a flaw in the permission checking for device
assignments requested via the kvm ioctl in the Linux kernel. A local user
could use this flaw to crash the system causing a denial of service.
(CVE-2011-4347)
Stephan Bärwolf discovered a flaw in the KVM (kernel-based virtual
machine) subsystem of the Linux kernel. A local unprivileged user can crash
use this flaw to crash VMs causing a deny of service. (CVE-2012-0045)
H. Peter Anvin reported a flaw in the Linux kernel that could crash the
system. A local user could exploit this flaw to crash the system.
(CVE-2012-1097)
A flaw was discovered in the Linux kernel's cgroups subset. A local
attacker could use this flaw to crash
Ubuntu
Linux kernel (Maverick backport) vulnerabilities
vendor_ubuntu·2012-04-12·CVSS 4.0
CVE-2011-4347 [MEDIUM] Linux kernel (Maverick backport) vulnerabilities
Title: Linux kernel (Maverick backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Sasha Levin discovered a flaw in the permission checking for device
assignments requested via the kvm ioctl in the Linux kernel. A local user
could use this flaw to crash the system causing a denial of service.
(CVE-2011-4347)
Stephan Bärwolf discovered a flaw in the KVM (kernel-based virtual
machine) subsystem of the Linux kernel. A local unprivileged user can crash
use this flaw to crash VMs causing a deny of service. (CVE-2012-0045)
H. Peter Anvin reported a flaw in the Linux kernel that could crash the
system. A local user could exploit this flaw to crash the system.
(CVE-2012-1097)
A flaw was discovered in the Linux kernel's cgroups subset. A local
attacker could use
Red Hat
kernel: mm: memcg: unregistring of events attached to the same eventfd can lead to oops
vendor_redhat·2012-02-24·CVSS 5.5
CVE-2012-1146 [MEDIUM] kernel: mm: memcg: unregistring of events attached to the same eventfd can lead to oops
kernel: mm: memcg: unregistring of events attached to the same eventfd can lead to oops
The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 does not properly handle multiple events that are attached to the same eventfd, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by registering memory threshold events.
Statement: This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5 as they did not include support for control groups. This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 6 as they did not include support for memory control groups threshold notifications.
GHSA
GHSA-83vv-q4vw-p24m: The mem_cgroup_usage_unregister_event function in mm/memcontrol
ghsa_unreviewed·2022-05-13
CVE-2012-1146 [MEDIUM] CWE-476 GHSA-83vv-q4vw-p24m: The mem_cgroup_usage_unregister_event function in mm/memcontrol
The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 does not properly handle multiple events that are attached to the same eventfd, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by registering memory threshold events.
OSV
CVE-2012-1146: The mem_cgroup_usage_unregister_event function in mm/memcontrol
osv·2012-03-07·CVSS 5.5
CVE-2012-1146 [MEDIUM] CVE-2012-1146: The mem_cgroup_usage_unregister_event function in mm/memcontrol
The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 does not properly handle multiple events that are attached to the same eventfd, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by registering memory threshold events.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-1146 kernel: mm: memcg: unregistring of events attached to the same eventfd can lead to oops [fedora-all]
bugzilla·2012-03-07·CVSS 5.5
CVE-2012-1146 [MEDIUM] CVE-2012-1146 kernel: mm: memcg: unregistring of events attached to the same eventfd can lead to oops [fedora-all]
CVE-2012-1146 kernel: mm: memcg: unregistring of events attached to the same eventfd can lead to oops [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedora
Bugzilla
CVE-2012-1146 kernel: mm: memcg: unregistring of events attached to the same eventfd can lead to oops
bugzilla·2012-03-07·CVSS 5.5
CVE-2012-1146 [MEDIUM] CVE-2012-1146 kernel: mm: memcg: unregistring of events attached to the same eventfd can lead to oops
CVE-2012-1146 kernel: mm: memcg: unregistring of events attached to the same eventfd can lead to oops
There is an issue when memcg unregisters events that were attached to
the same eventfd:
- On the first call mem_cgroup_usage_unregister_event() removes all
events attached to a given eventfd, and if there were no events left,
thresholds->primary would become NULL;
- Since there were several events registered, cgroups core will call
mem_cgroup_usage_unregister_event() again, but now kernel will oops,
as the function doesn't expect that threshold->primary may be NULL.
FWIW, w/o the patch the following oops may be observed:
BUG: unable to handle kernel NULL pointer dereference at 0000000000000004
IP: [] mem_cgroup_usage_unregister_event+0x9c/0x1f0
Pid: 574, comm: kworker/0:2 Not tainted
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=371528caec553785c37f73fa3926ea0de84f986fhttp://lists.fedoraproject.org/pipermail/package-announce/2012-March/075781.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00021.htmlhttp://secunia.com/advisories/48898http://secunia.com/advisories/48964http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.10http://www.openwall.com/lists/oss-security/2012/03/07/3https://bugzilla.redhat.com/show_bug.cgi?id=800813https://exchange.xforce.ibmcloud.com/vulnerabilities/73711https://github.com/torvalds/linux/commit/371528caec553785c37f73fa3926ea0de84f986fhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=371528caec553785c37f73fa3926ea0de84f986fhttp://lists.fedoraproject.org/pipermail/package-announce/2012-March/075781.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00021.htmlhttp://secunia.com/advisories/48898http://secunia.com/advisories/48964http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.10http://www.openwall.com/lists/oss-security/2012/03/07/3https://bugzilla.redhat.com/show_bug.cgi?id=800813https://exchange.xforce.ibmcloud.com/vulnerabilities/73711https://github.com/torvalds/linux/commit/371528caec553785c37f73fa3926ea0de84f986f
2012-05-17
Published