CVE-2012-2390
published 2012-06-13CVE-2012-2390: Memory leak in mm/hugetlb.c in the Linux kernel before 3.4.2 allows local users to cause a denial of service (memory consumption or system crash) via invalid…
PriorityP413medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.52%
41.6th percentile
Memory leak in mm/hugetlb.c in the Linux kernel before 3.4.2 allows local users to cause a denial of service (memory consumption or system crash) via invalid MAP_HUGETLB mmap operations.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.19-1 (bookworm) | linux 3.2.19-1 (bookworm) |
| linux | linux_kernel | <= 3.4.1 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 3.2.19-1 | 3.2.19-1 |
| linux | linux_kernel | >= 0 < 3.2.19-1 | 3.2.19-1 |
| linux | linux_kernel | >= 0 < 3.2.19-1 | 3.2.19-1 |
| linux | linux_kernel | >= 0 < 3.2.19-1 | 3.2.19-1 |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_ubuntu7.2HIGH
vendor_debian4.9LOW
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities
vendor_ubuntu·2012-08-14·CVSS 7.2
CVE-2012-2136 [HIGH] Linux kernel (Oneiric backport) vulnerabilities
Title: Linux kernel (Oneiric backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
An error was discovered in the Linux kernel's network TUN/TAP device
implementation. A local user with access to the TUN/TAP interface (which is
not available to unprivileged users until granted by a root user) could
exploit this flaw to crash the system or potential gain administrative
privileges. (CVE-2012-2136)
Ulrich Obergfell discovered an error in the Linux kernel's memory
management subsystem on 32 bit PAE systems with more than 4GB of memory
installed. A local unprivileged user could exploit this flaw to crash the
system. (CVE-2012-2373)
An error was discovered in the Linux kernel's memory subsystem (hugetlb).
An unprivileged local user could exploit this flaw to ca
Ubuntu
Linux kernel (Natty backport) vulnerabilities
vendor_ubuntu·2012-08-14·CVSS 7.2
CVE-2012-2136 [HIGH] Linux kernel (Natty backport) vulnerabilities
Title: Linux kernel (Natty backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
An error was discovered in the Linux kernel's network TUN/TAP device
implementation. A local user with access to the TUN/TAP interface (which is
not available to unprivileged users until granted by a root user) could
exploit this flaw to crash the system or potential gain administrative
privileges. (CVE-2012-2136)
A flaw was found in the Linux kernel's Reliable Datagram Sockets (RDS)
protocol implementation. A local, unprivileged user could use this flaw to
cause a denial of service. (CVE-2012-2372)
An error was discovered in the Linux kernel's memory subsystem (hugetlb).
An unprivileged local user could exploit this flaw to cause a denial of
service (crash the system). (CVE-
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-08-10·CVSS 7.2
CVE-2012-2136 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
An error was discovered in the Linux kernel's network TUN/TAP device
implementation. A local user with access to the TUN/TAP interface (which is
not available to unprivileged users until granted by a root user) could
exploit this flaw to crash the system or potential gain administrative
privileges. (CVE-2012-2136)
Ulrich Obergfell discovered an error in the Linux kernel's memory
management subsystem on 32 bit PAE systems with more than 4GB of memory
installed. A local unprivileged user could exploit this flaw to crash the
system. (CVE-2012-2373)
An error was discovered in the Linux kernel's memory subsystem (hugetlb).
An unprivileged local user could exploit this flaw to cause a denial of
ser
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2012-08-10·CVSS 7.2
CVE-2012-2136 [HIGH] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
An error was discovered in the Linux kernel's network TUN/TAP device
implementation. A local user with access to the TUN/TAP interface (which is
not available to unprivileged users until granted by a root user) could
exploit this flaw to crash the system or potential gain administrative
privileges. (CVE-2012-2136)
An error was discovered in the Linux kernel's memory subsystem (hugetlb).
An unprivileged local user could exploit this flaw to cause a denial of
service (crash the system). (CVE-2012-2390)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been gi
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-08-10·CVSS 7.2
CVE-2012-2136 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
An error was discovered in the Linux kernel's network TUN/TAP device
implementation. A local user with access to the TUN/TAP interface (which is
not available to unprivileged users until granted by a root user) could
exploit this flaw to crash the system or potential gain administrative
privileges. (CVE-2012-2136)
An error was discovered in the Linux kernel's memory subsystem (hugetlb).
An unprivileged local user could exploit this flaw to cause a denial of
service (crash the system). (CVE-2012-2390)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-08-10·CVSS 7.2
CVE-2012-2136 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
An error was discovered in the Linux kernel's network TUN/TAP device
implementation. A local user with access to the TUN/TAP interface (which is
not available to unprivileged users until granted by a root user) could
exploit this flaw to crash the system or potential gain administrative
privileges. (CVE-2012-2136)
A flaw was found in the Linux kernel's Reliable Datagram Sockets (RDS)
protocol implementation. A local, unprivileged user could use this flaw to
cause a denial of service. (CVE-2012-2372)
An error was discovered in the Linux kernel's memory subsystem (hugetlb).
An unprivileged local user could exploit this flaw to cause a denial of
service (crash the system). (CVE-2012-2390)
Instr
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2012-07-23
CVE-2012-2390 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash under certain conditions.
An error was discovered in the Linux kernel's memory subsystem (hugetlb).
An unprivileged local user could exploit this flaw to cause a denial of
service (crash the system).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g.
Ubuntu
Linux kernel (OMAP4) vulnerability
vendor_ubuntu·2012-07-17
CVE-2012-2390 Linux kernel (OMAP4) vulnerability
Title: Linux kernel (OMAP4) vulnerability
Summary: The system could be made to crash under certain conditions.
An error was discovered in the Linux kernel's memory subsystem (hugetlb).
An unprivileged local user could exploit this flaw to cause a denial of
service (crash the system).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackag
Red Hat
kernel: huge pages: memory leak on mmap failure
vendor_redhat·2012-05-17·CVSS 4.9
CVE-2012-2390 [MEDIUM] CWE-401 kernel: huge pages: memory leak on mmap failure
kernel: huge pages: memory leak on mmap failure
Memory leak in mm/hugetlb.c in the Linux kernel before 3.4.2 allows local users to cause a denial of service (memory consumption or system crash) via invalid MAP_HUGETLB mmap operations.
Statement: This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5 as they did not include the upstream commit 84afd99b that introduced this issue. Future kernel updates for Red Hat Enterprise Linux 6 may address this issue.
This has been addressed in Red Hat Enterprise Linux Red Hat Enterprise MRG 2 via https://rhn.redhat.com/errata/RHSA-2012-1150.html
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux Extended Update Support 6.3) - Affected
Debian
CVE-2012-2390: linux - Memory leak in mm/hugetlb.c in the Linux kernel before 3.4.2 allows local users ...
vendor_debian·2012·CVSS 4.9
CVE-2012-2390 [MEDIUM] CVE-2012-2390: linux - Memory leak in mm/hugetlb.c in the Linux kernel before 3.4.2 allows local users ...
Memory leak in mm/hugetlb.c in the Linux kernel before 3.4.2 allows local users to cause a denial of service (memory consumption or system crash) via invalid MAP_HUGETLB mmap operations.
Scope: local
bookworm: resolved (fixed in 3.2.19-1)
bullseye: resolved (fixed in 3.2.19-1)
forky: resolved (fixed in 3.2.19-1)
sid: resolved (fixed in 3.2.19-1)
trixie: resolved (fixed in 3.2.19-1)
GHSA
GHSA-h487-53rw-hpv4: Memory leak in mm/hugetlb
ghsa_unreviewed·2022-05-17
CVE-2012-2390 [MEDIUM] GHSA-h487-53rw-hpv4: Memory leak in mm/hugetlb
Memory leak in mm/hugetlb.c in the Linux kernel before 3.4.2 allows local users to cause a denial of service (memory consumption or system crash) via invalid MAP_HUGETLB mmap operations.
OSV
CVE-2012-2390: Memory leak in mm/hugetlb
osv·2012-06-13·CVSS 4.9
CVE-2012-2390 [MEDIUM] CVE-2012-2390: Memory leak in mm/hugetlb
Memory leak in mm/hugetlb.c in the Linux kernel before 3.4.2 allows local users to cause a denial of service (memory consumption or system crash) via invalid MAP_HUGETLB mmap operations.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2390 kernel: huge pages: memory leak on mmap failure [fedora-all]
bugzilla·2012-05-23·CVSS 4.9
CVE-2012-2390 [MEDIUM] CVE-2012-2390 kernel: huge pages: memory leak on mmap failure [fedora-all]
CVE-2012-2390 kernel: huge pages: memory leak on mmap failure [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&
Bugzilla
CVE-2012-2390 kernel: huge pages: memory leak on mmap failure
bugzilla·2012-05-23·CVSS 4.9
CVE-2012-2390 [MEDIUM] CVE-2012-2390 kernel: huge pages: memory leak on mmap failure
CVE-2012-2390 kernel: huge pages: memory leak on mmap failure
Description of problem:
When called for anonymous (non-shared) mappings, hugetlb_reserve_pages() does a resv_map_alloc(). It depends on code in hugetlbfs's vm_ops->close() to release that allocation.
However, in the mmap() failure path, we do a plain unmap_region() without the remove_vma() which actually calls vm_ops->close().
An unprivileged local user could use this flaw to crash the system.
References:
http://www.spinics.net/lists/linux-mm/msg34763.html
Proposed upstream fix:
https://lkml.org/lkml/2012/5/21/385
Discussion:
Created kernel tracking bugs for this issue
Affects: fedora-all [bug 824352]
---
Added CVE as per http://www.openwall.com/lists/oss-security/2012/05/23/14
---
Upstream commits:
c50ac050811d64856
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c50ac050811d6485616a193eb0f37bfbd191cc89http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.4.2http://www.openwall.com/lists/oss-security/2012/05/23/14http://www.ubuntu.com/usn/USN-1515-1http://www.ubuntu.com/usn/USN-1535-1https://bugzilla.redhat.com/show_bug.cgi?id=824345https://github.com/torvalds/linux/commit/c50ac050811d6485616a193eb0f37bfbd191cc89http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c50ac050811d6485616a193eb0f37bfbd191cc89http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.4.2http://www.openwall.com/lists/oss-security/2012/05/23/14http://www.ubuntu.com/usn/USN-1515-1http://www.ubuntu.com/usn/USN-1535-1https://bugzilla.redhat.com/show_bug.cgi?id=824345https://github.com/torvalds/linux/commit/c50ac050811d6485616a193eb0f37bfbd191cc89
2012-06-13
Published