The int3 handler in the Linux kernel before 3.3 relies on a per-CPU debug stack, which allows local users to cause a denial of service (stack corruption and panic) via a crafted application that triggers certain lock contention.
References
Link | Resource |
---|---|
https://git.kernel.org/pub/scm/linux/kernel/git/rt/linux-stable-rt.git/commit/?id=e5d4e1c3ccee18c68f23d62ba77bda26e893d4f0 | Mailing List Patch Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=794557 | Issue Tracking Third Party Advisory |
https://git.kernel.org/pub/scm/linux/kernel/git/rt/linux-stable-rt.git/commit/?id=bcf6b1d78c0bde228929c388978ed3af9a623463 | Mailing List Patch Vendor Advisory |
Configurations
Information
Published : 2020-02-12 06:15
Updated : 2020-02-14 10:56
NVD link : CVE-2012-0810
Mitre link : CVE-2012-0810
JSON object : View
CWE
CWE-400
Uncontrolled Resource Consumption
Products Affected
linux
- linux_kernel