CVE-2016-2847

Severity
6.2MEDIUM
EPSS
0.1%
top 77.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 27
Latest updateMay 14

Description

fs/pipe.c in the Linux kernel before 4.5 does not limit the amount of unread data in pipes, which allows local users to cause a denial of service (memory consumption) by creating many pipes with non-default sizes.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.5 | Impact: 3.6

Affected Packages10 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-g874-pwj2-p4wh: fs/pipe2022-05-14
CVEList
CVE-2016-2847: fs/pipe2016-04-27
OSV
CVE-2016-2847: fs/pipe2016-04-27

📋Vendor Advisories

12
Ubuntu
Linux kernel vulnerabilities2016-05-09
Ubuntu
Linux kernel (OMAP4) vulnerabilities2016-05-09
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities2016-05-06
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities2016-04-06
Ubuntu
Linux kernel (Wily HWE) vulnerabilities2016-04-06

💬Community

2
Bugzilla
CVE-2016-2847 kernel: pipe: limit the per-user amount of pages allocated in pipes2016-03-01
Bugzilla
CVE-2016-2847 kernel: pipe: limit the per-user amount of pages allocated in pipes [fedora-all]2016-03-01