CVE-2015-4170

Severity
4.7MEDIUM
EPSS
0.1%
top 80.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 2
Latest updateMay 17

Description

Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem.c in the Linux kernel before 3.13-rc4-next-20131218 allows local users to cause a denial of service (ldsem_down_read and ldsem_down_write deadlock) by establishing a new tty thread during shutdown of a previous tty thread.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6

Affected Packages3 packages

NVDlinux/linux_kernel3.13.3
Debianlinux< 3.13.4-1+3

Also affects: Enterprise Linux 7.1, 7.1_ppc64

Patches

🔴Vulnerability Details

3
GHSA
GHSA-mqxq-v3w5-xvj4: Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem2022-05-17
CVEList
CVE-2015-4170: Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem2016-05-02
OSV
CVE-2015-4170: Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem2016-05-02

📋Vendor Advisories

2
Red Hat
kernel: pty layer race condition on tty ldisc shutdown.2015-01-19
Debian
CVE-2015-4170: linux - Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem.c in the L...2015

💬Community

1
Bugzilla
CVE-2015-4170 kernel: pty layer race condition on tty ldisc shutdown.2015-05-06