CVE-2014-8171
published 2018-02-09CVE-2014-8171: The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes within a…
PriorityP418medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.39%
31.4th percentile
The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes within a memory-constrained cgroup.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.12.6-1 (bookworm) | linux 3.12.6-1 (bookworm) |
| linux | linux_kernel | >= 0 < 3.12.6-1 | 3.12.6-1 |
| linux | linux_kernel | >= 0 < 3.12.6-1 | 3.12.6-1 |
| linux | linux_kernel | >= 0 < 3.12.6-1 | 3.12.6-1 |
| linux | linux_kernel | >= 0 < 3.12.6-1 | 3.12.6-1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_mrg | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: memcg: OOM handling DoS
vendor_redhat·2015-04-21·CVSS 5.5
CVE-2014-8171 [MEDIUM] CWE-833 kernel: memcg: OOM handling DoS
kernel: memcg: OOM handling DoS
The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes within a memory-constrained cgroup.
It was found that the Linux kernel memory resource controller's (memcg) handling of OOM (out of memory) conditions could lead to deadlocks. An attacker able to continuously spawn new processes within a single memory-constrained cgroup during an OOM event could use this flaw to lock up the system.
Statement: This issue does not affect the Linux kernel versions as shipped with Red Hat Enterprise Linux 5. This issue does affect the Linux kernel versions as shipped with Red Hat Enterprise Linux 6, 7 and Red Hat Enterprise MRG 2. Future updates may address this issue in the respe
Debian
CVE-2014-8171: linux - The memory resource controller (aka memcg) in the Linux kernel allows local user...
vendor_debian·2014·CVSS 5.5
CVE-2014-8171 [MEDIUM] CVE-2014-8171: linux - The memory resource controller (aka memcg) in the Linux kernel allows local user...
The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes within a memory-constrained cgroup.
Scope: local
bookworm: resolved (fixed in 3.12.6-1)
bullseye: resolved (fixed in 3.12.6-1)
forky: resolved (fixed in 3.12.6-1)
sid: resolved (fixed in 3.12.6-1)
trixie: resolved (fixed in 3.12.6-1)
GHSA
GHSA-fj89-88c3-v65v: The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes wi
ghsa_unreviewed·2022-05-13
CVE-2014-8171 [MEDIUM] GHSA-fj89-88c3-v65v: The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes wi
The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes within a memory-constrained cgroup.
OSV
CVE-2014-8171: The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes wi
osv·2018-02-09·CVSS 5.5
CVE-2014-8171 [MEDIUM] CVE-2014-8171: The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes wi
The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes within a memory-constrained cgroup.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2015-0864.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2152.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2411.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0068.htmlhttp://www.securityfocus.com/bid/74293https://bugzilla.redhat.com/show_bug.cgi?id=1198109http://rhn.redhat.com/errata/RHSA-2015-0864.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2152.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2411.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0068.htmlhttp://www.securityfocus.com/bid/74293https://bugzilla.redhat.com/show_bug.cgi?id=1198109
2018-02-09
Published