CVE-2015-4170
published 2016-05-02CVE-2015-4170: Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem.c in the Linux kernel before 3.13-rc4-next-20131218 allows local users to cause a denial…
PriorityP414medium4.7CVSS 3.0
AVLACHPRNUIRSUCNINAH
EPSS
0.33%
24.6th percentile
Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem.c in the Linux kernel before 3.13-rc4-next-20131218 allows local users to cause a denial of service (ldsem_down_read and ldsem_down_write deadlock) by establishing a new tty thread during shutdown of a previous tty thread.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.13.4-1 (bookworm) | linux 3.13.4-1 (bookworm) |
| linux | linux_kernel | <= 3.13.3 | — |
| linux | linux_kernel | >= 0 < 3.13.4-1 | 3.13.4-1 |
| linux | linux_kernel | >= 0 < 3.13.4-1 | 3.13.4-1 |
| linux | linux_kernel | >= 0 < 3.13.4-1 | 3.13.4-1 |
| linux | linux_kernel | >= 0 < 3.13.4-1 | 3.13.4-1 |
| redhat | enterprise_linux_compute_node_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_power_big_endian_eus | — | — |
| redhat | enterprise_linux_for_power_little_endian_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
CVSS provenance
nvdv3.04.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mqxq-v3w5-xvj4: Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem
ghsa_unreviewed·2022-05-17
CVE-2015-4170 [MEDIUM] CWE-362 GHSA-mqxq-v3w5-xvj4: Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem
Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem.c in the Linux kernel before 3.13-rc4-next-20131218 allows local users to cause a denial of service (ldsem_down_read and ldsem_down_write deadlock) by establishing a new tty thread during shutdown of a previous tty thread.
OSV
CVE-2015-4170: Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem
osv·2016-05-02·CVSS 4.7
CVE-2015-4170 [MEDIUM] CVE-2015-4170: Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem
Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem.c in the Linux kernel before 3.13-rc4-next-20131218 allows local users to cause a denial of service (ldsem_down_read and ldsem_down_write deadlock) by establishing a new tty thread during shutdown of a previous tty thread.
Red Hat
kernel: pty layer race condition on tty ldisc shutdown.
vendor_redhat·2015-01-19·CVSS 4.7
CVE-2015-4170 [MEDIUM] CWE-667 kernel: pty layer race condition on tty ldisc shutdown.
kernel: pty layer race condition on tty ldisc shutdown.
Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem.c in the Linux kernel before 3.13-rc4-next-20131218 allows local users to cause a denial of service (ldsem_down_read and ldsem_down_write deadlock) by establishing a new tty thread during shutdown of a previous tty thread.
A flaw was discovered in the way the Linux kernel's TTY subsystem handled the tty shutdown phase. A local, unprivileged user could use this flaw to cause denial of service on the system by holding a reference to the ldisc lock during tty shutdown, causing a deadlock.
Statement: This issue does not affect the Linux kernels as shipped with Red Hat Enterprise Linux 5, 6.
This issue affects the Linux kernel packages kernel as shipped with Red Hat E
Debian
CVE-2015-4170: linux - Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem.c in the L...
vendor_debian·2015·CVSS 4.7
CVE-2015-4170 [MEDIUM] CVE-2015-4170: linux - Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem.c in the L...
Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem.c in the Linux kernel before 3.13-rc4-next-20131218 allows local users to cause a denial of service (ldsem_down_read and ldsem_down_write deadlock) by establishing a new tty thread during shutdown of a previous tty thread.
Scope: local
bookworm: resolved (fixed in 3.13.4-1)
bullseye: resolved (fixed in 3.13.4-1)
forky: resolved (fixed in 3.13.4-1)
sid: resolved (fixed in 3.13.4-1)
trixie: resolved (fixed in 3.13.4-1)
No detection rules found.
No public exploits indexed.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cf872776fc84128bb779ce2b83a37c884c3203aehttp://www.openwall.com/lists/oss-security/2015/05/26/1http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/74820https://access.redhat.com/errata/RHSA-2016:1395https://bugzilla.redhat.com/show_bug.cgi?id=1218879https://github.com/torvalds/linux/commit/cf872776fc84128bb779ce2b83a37c884c3203aehttps://www.kernel.org/pub/linux/kernel/next/patch-v3.13-rc4-next-20131218.xzhttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cf872776fc84128bb779ce2b83a37c884c3203aehttp://www.openwall.com/lists/oss-security/2015/05/26/1http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/74820https://access.redhat.com/errata/RHSA-2016:1395https://bugzilla.redhat.com/show_bug.cgi?id=1218879https://github.com/torvalds/linux/commit/cf872776fc84128bb779ce2b83a37c884c3203aehttps://www.kernel.org/pub/linux/kernel/next/patch-v3.13-rc4-next-20131218.xz
2016-05-02
Published