CVE-2016-2550
published 2016-04-27CVE-2016-2550: The Linux kernel before 4.5 allows local users to bypass file-descriptor limits and cause a denial of service (memory consumption) by leveraging incorrect…
PriorityP420medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.51%
40.5th percentile
The Linux kernel before 4.5 allows local users to bypass file-descriptor limits and cause a denial of service (memory consumption) by leveraging incorrect tracking of descriptor ownership and sending each descriptor over a UNIX socket before closing it. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-4312.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.4.4-1 (bookworm) | linux 4.4.4-1 (bookworm) |
| linux | linux_kernel | <= 4.4.8 | — |
| linux | linux_kernel | >= 0 < 4.4.4-1 | 4.4.4-1 |
| linux | linux_kernel | >= 0 < 4.4.4-1 | 4.4.4-1 |
| linux | linux_kernel | >= 0 < 4.4.4-1 | 4.4.4-1 |
| linux | linux_kernel | >= 0 < 4.4.4-1 | 4.4.4-1 |
| linux | linux_kernel | >= 0 < 3.13.0-85.129 | 3.13.0-85.129 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Utopic HWE) regression
vendor_ubuntu·2016-04-11·CVSS 4.6
[MEDIUM] Linux kernel (Utopic HWE) regression
Title: Linux kernel (Utopic HWE) regression
Summary: USN 2948-1 introduced a regression in the Ubuntu 14.10 Linux kernel
backported to Ubuntu 14.04 LTS.
USN-2948-1 fixed vulnerabilities in the Ubuntu 14.10 Linux kernel
backported to Ubuntu 14.04 LTS. An incorrect reference counting
fix in the radeon driver introduced a regression that could cause a
system crash. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7566)
Ralf Spenneberg discovered that the usbvision driver in the Linux kernel
did not properly
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2016-04-06·CVSS 9.8
CVE-2015-8812 [CRITICAL] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Venkatesh Pottem discovered a use-after-free vulnerability in the Linux
kernel's CXGB3 driver. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2015-8812)
Xiaofei Rex Guo discovered a timing side channel vulnerability in the Linux
Extended Verification Module (EVM). An attacker could use this to affect
system integrity. (CVE-2016-2085)
David Herrmann discovered that the Linux kernel incorrectly accounted file
descriptors to the original opener for in-flight file descriptors sent over
a unix domain socket. A local attacker could use this to cause a denial of
service (resource exhaustion). (CVE-2016-2550)
It was d
Ubuntu
Linux kernel (Wily HWE) vulnerabilities
vendor_ubuntu·2016-04-06·CVSS 4.9
CVE-2015-7833 [MEDIUM] Linux kernel (Wily HWE) vulnerabilities
Title: Linux kernel (Wily HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ralf Spenneberg discovered that the usbvision driver in the Linux kernel
did not properly validate the interfaces and endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7833)
Venkatesh Pottem discovered a use-after-free vulnerability in the Linux
kernel's CXGB3 driver. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2015-8812)
Xiaofei Rex Guo discovered a timing side channel vulnerability in the Linux
Extended Verification Module (EVM). An attacker could use this to affect
system integrity. (CVE-2016-2085)
It was discovered that the extende
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-04-06·CVSS 9.8
CVE-2015-8812 [CRITICAL] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Venkatesh Pottem discovered a use-after-free vulnerability in the Linux
kernel's CXGB3 driver. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2015-8812)
Xiaofei Rex Guo discovered a timing side channel vulnerability in the Linux
Extended Verification Module (EVM). An attacker could use this to affect
system integrity. (CVE-2016-2085)
David Herrmann discovered that the Linux kernel incorrectly accounted file
descriptors to the original opener for in-flight file descriptors sent over
a unix domain socket. A local attacker could use this to cause a denial of
service (resource exhaustion). (CVE-2016-2550)
It was discovered tha
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-04-06·CVSS 4.9
CVE-2015-7833 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ralf Spenneberg discovered that the usbvision driver in the Linux kernel
did not properly validate the interfaces and endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7833)
Venkatesh Pottem discovered a use-after-free vulnerability in the Linux
kernel's CXGB3 driver. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2015-8812)
Xiaofei Rex Guo discovered a timing side channel vulnerability in the Linux
Extended Verification Module (EVM). An attacker could use this to affect
system integrity. (CVE-2016-2085)
It was discovered that the extended Berkeley
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2016-04-06·CVSS 4.9
CVE-2015-7833 [MEDIUM] Linux kernel (Raspberry Pi 2) vulnerabilities
Title: Linux kernel (Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ralf Spenneberg discovered that the usbvision driver in the Linux kernel
did not properly validate the interfaces and endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7833)
Venkatesh Pottem discovered a use-after-free vulnerability in the Linux
kernel's CXGB3 driver. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2015-8812)
Xiaofei Rex Guo discovered a timing side channel vulnerability in the Linux
Extended Verification Module (EVM). An attacker could use this to affect
system integrity. (CVE-2016-2085)
It was discovered that the e
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities
vendor_ubuntu·2016-04-06·CVSS 9.8
CVE-2015-8812 [CRITICAL] Linux kernel (Vivid HWE) vulnerabilities
Title: Linux kernel (Vivid HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Venkatesh Pottem discovered a use-after-free vulnerability in the Linux
kernel's CXGB3 driver. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2015-8812)
Xiaofei Rex Guo discovered a timing side channel vulnerability in the Linux
Extended Verification Module (EVM). An attacker could use this to affect
system integrity. (CVE-2016-2085)
David Herrmann discovered that the Linux kernel incorrectly accounted file
descriptors to the original opener for in-flight file descriptors sent over
a unix domain socket. A local attacker could use this to cause a denial of
service (resource exhaustion). (CVE-2016-2550)
It was di
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2016-04-06·CVSS 4.6
CVE-2015-7566 [MEDIUM] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7566)
Ralf Spenneberg discovered that the usbvision driver in the Linux kernel
did not properly validate the interfaces and endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7833)
Venkatesh Pottem discovered a use-after-free vulnerability in the Linux
kernel's CXGB3 driver. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arb
Red Hat
kernel: incorrectly accounted in-flight fds
vendor_redhat·2016-02-22·CVSS 6.2
CVE-2016-2550 [MEDIUM] CWE-400 kernel: incorrectly accounted in-flight fds
kernel: incorrectly accounted in-flight fds
The Linux kernel before 4.5 allows local users to bypass file-descriptor limits and cause a denial of service (memory consumption) by leveraging incorrect tracking of descriptor ownership and sending each descriptor over a UNIX socket before closing it. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-4312.
A resource-exhaustion vulnerability was found in the kernel, where an unprivileged process could allocate and accumulate far more file descriptors than the process' limit. A local, unauthenticated user could exploit this flaw by sending file descriptors over a Unix socket and then closing them to keep the process' fd count low, thereby creating kernel-memory or file-descriptors exhaustion (denial of service).
Stateme
Debian
CVE-2016-2550: linux - The Linux kernel before 4.5 allows local users to bypass file-descriptor limits ...
vendor_debian·2016·CVSS 6.2
CVE-2016-2550 [MEDIUM] CVE-2016-2550: linux - The Linux kernel before 4.5 allows local users to bypass file-descriptor limits ...
The Linux kernel before 4.5 allows local users to bypass file-descriptor limits and cause a denial of service (memory consumption) by leveraging incorrect tracking of descriptor ownership and sending each descriptor over a UNIX socket before closing it. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-4312.
Scope: local
bookworm: resolved (fixed in 4.4.4-1)
bullseye: resolved (fixed in 4.4.4-1)
forky: resolved (fixed in 4.4.4-1)
sid: resolved (fixed in 4.4.4-1)
trixie: resolved (fixed in 4.4.4-1)
GHSA
GHSA-w67r-pc7p-x294: The Linux kernel before 4
ghsa_unreviewed·2022-05-14·CVSS 6.2
CVE-2016-2550 [MEDIUM] GHSA-w67r-pc7p-x294: The Linux kernel before 4
The Linux kernel before 4.5 allows local users to bypass file-descriptor limits and cause a denial of service (memory consumption) by leveraging incorrect tracking of descriptor ownership and sending each descriptor over a UNIX socket before closing it. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-4312.
OSV
CVE-2016-2550: The Linux kernel before 4
osv·2016-04-27·CVSS 6.2
CVE-2016-2550 [MEDIUM] CVE-2016-2550: The Linux kernel before 4
The Linux kernel before 4.5 allows local users to bypass file-descriptor limits and cause a denial of service (memory consumption) by leveraging incorrect tracking of descriptor ownership and sending each descriptor over a UNIX socket before closing it. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-4312.
OSV
linux-lts-utopic regression
osv·2016-04-11·CVSS 4.6
[MEDIUM] linux-lts-utopic regression
linux-lts-utopic regression
USN-2948-1 fixed vulnerabilities in the Ubuntu 14.10 Linux kernel
backported to Ubuntu 14.04 LTS. An incorrect reference counting
fix in the radeon driver introduced a regression that could cause a
system crash. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7566)
Ralf Spenneberg discovered that the usbvision driver in the Linux kernel
did not properly validate the interfaces and endpoints reported by the
device. An attacker with physical access could cause a denial of service
OSV
linux vulnerabilities
osv·2016-04-06·CVSS 9.8
CVE-2015-8812 [CRITICAL] linux vulnerabilities
linux vulnerabilities
Venkatesh Pottem discovered a use-after-free vulnerability in the Linux
kernel's CXGB3 driver. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2015-8812)
Xiaofei Rex Guo discovered a timing side channel vulnerability in the Linux
Extended Verification Module (EVM). An attacker could use this to affect
system integrity. (CVE-2016-2085)
David Herrmann discovered that the Linux kernel incorrectly accounted file
descriptors to the original opener for in-flight file descriptors sent over
a unix domain socket. A local attacker could use this to cause a denial of
service (resource exhaustion). (CVE-2016-2550)
It was discovered that the Linux kernel did not enforce limits on the
amount of data allocated
OSV
linux-lts-utopic vulnerabilities
osv·2016-04-06·CVSS 4.6
CVE-2015-7566 [MEDIUM] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7566)
Ralf Spenneberg discovered that the usbvision driver in the Linux kernel
did not properly validate the interfaces and endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7833)
Venkatesh Pottem discovered a use-after-free vulnerability in the Linux
kernel's CXGB3 driver. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2015-8812)
It was discovered that a race condition existe
OSV
linux-lts-wily vulnerabilities
osv·2016-04-06·CVSS 4.9
CVE-2015-7833 [MEDIUM] linux-lts-wily vulnerabilities
linux-lts-wily vulnerabilities
Ralf Spenneberg discovered that the usbvision driver in the Linux kernel
did not properly validate the interfaces and endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7833)
Venkatesh Pottem discovered a use-after-free vulnerability in the Linux
kernel's CXGB3 driver. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2015-8812)
Xiaofei Rex Guo discovered a timing side channel vulnerability in the Linux
Extended Verification Module (EVM). An attacker could use this to affect
system integrity. (CVE-2016-2085)
It was discovered that the extended Berkeley Packet Filter (eBPF)
implementation in the Linux kernel did not c
OSV
linux-lts-vivid vulnerabilities
osv·2016-04-06·CVSS 9.8
CVE-2015-8812 [CRITICAL] linux-lts-vivid vulnerabilities
linux-lts-vivid vulnerabilities
Venkatesh Pottem discovered a use-after-free vulnerability in the Linux
kernel's CXGB3 driver. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2015-8812)
Xiaofei Rex Guo discovered a timing side channel vulnerability in the Linux
Extended Verification Module (EVM). An attacker could use this to affect
system integrity. (CVE-2016-2085)
David Herrmann discovered that the Linux kernel incorrectly accounted file
descriptors to the original opener for in-flight file descriptors sent over
a unix domain socket. A local attacker could use this to cause a denial of
service (resource exhaustion). (CVE-2016-2550)
It was discovered that the Linux kernel did not enforce limits on the
amount of data
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2550 kernel: incorrectly accounted in-flight fds
bugzilla·2016-02-24·CVSS 6.2
CVE-2016-2550 [MEDIUM] CVE-2016-2550 kernel: incorrectly accounted in-flight fds
CVE-2016-2550 kernel: incorrectly accounted in-flight fds
The fix for CVE-2013-4312 incorrectly accounted the
number of in-flight fds over a unix domain socket to the original
opener of the file-descriptor. This allows another process to
arbitrary deplete the original file-openers resource limit for the
maximum of open files.
CVE-ID request and assignment:
http://seclists.org/oss-sec/2016/q1/401
http://seclists.org/oss-sec/2016/q1/412
Upstream patch:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=415e3d3e90ce9e18727e8843ae343eda5a58fad6
Commit, which introduced the issue (it was addressing CVE-2013-4312):
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=712f4aad406bb1ed67f3f98d04c044191f0ff593
Discussion:
Created kernel trackin
Bugzilla
CVE-2016-2550 kernel: incorrectly accounted in-flight fds [fedora-all]
bugzilla·2016-02-24·CVSS 5.5
CVE-2016-2550 [MEDIUM] CVE-2016-2550 kernel: incorrectly accounted in-flight fds [fedora-all]
CVE-2016-2550 kernel: incorrectly accounted in-flight fds [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
arXiv
Characteristics, Root Causes, and Detection of Incomplete Security Bug Fixes in the Linux Kernel
arxiv_fulltext·2025-11-21
Characteristics, Root Causes, and Detection of Incomplete Security Bug Fixes in the Linux Kernel
Characteristics, Root Causes, and Detection of
Incomplete Security Bug Fixes in the Linux Kernel
Qiang Liu^1All work was done by Aug., 2022.,
Wenlong Zhang^1,
Muhui Jiang^2,1,
Lei Wu^1,
Yajin Zhou^1
^1Zhejiang University,
^2The Hong Kong Polytechnic University
## Abstract
Security bugs in the Linux kernel emerge endlessly and have attracted much
attention.
However, fixing security bugs in the Linux kernel could be incomplete due to
human mistakes.
Specifically, an incomplete fix fails to repair all the original security
defects in the software, fails to properly repair the original security defects,
or introduces new ones.
In this paper, we study the fixes of incomplete security bugs in the Linux
kernel for the first time, and reveal their characteristics, root causes as well
as de
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=415e3d3e90ce9e18727e8843ae343eda5a58fad6http://www.debian.org/security/2016/dsa-3503http://www.openwall.com/lists/oss-security/2016/02/23/2http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.ubuntu.com/usn/USN-2946-1http://www.ubuntu.com/usn/USN-2946-2http://www.ubuntu.com/usn/USN-2947-1http://www.ubuntu.com/usn/USN-2947-2http://www.ubuntu.com/usn/USN-2947-3http://www.ubuntu.com/usn/USN-2948-1http://www.ubuntu.com/usn/USN-2948-2http://www.ubuntu.com/usn/USN-2949-1https://bugzilla.redhat.com/show_bug.cgi?id=1311517https://github.com/torvalds/linux/commit/415e3d3e90ce9e18727e8843ae343eda5a58fad6http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=415e3d3e90ce9e18727e8843ae343eda5a58fad6http://www.debian.org/security/2016/dsa-3503http://www.openwall.com/lists/oss-security/2016/02/23/2http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.ubuntu.com/usn/USN-2946-1http://www.ubuntu.com/usn/USN-2946-2http://www.ubuntu.com/usn/USN-2947-1http://www.ubuntu.com/usn/USN-2947-2http://www.ubuntu.com/usn/USN-2947-3http://www.ubuntu.com/usn/USN-2948-1http://www.ubuntu.com/usn/USN-2948-2http://www.ubuntu.com/usn/USN-2949-1https://bugzilla.redhat.com/show_bug.cgi?id=1311517https://github.com/torvalds/linux/commit/415e3d3e90ce9e18727e8843ae343eda5a58fad6
2016-04-27
Published