The __munlock_pagevec function in mm/mlock.c in the Linux kernel before 4.11.4 allows local users to cause a denial of service (NR_MLOCK accounting corruption) via crafted use of mlockall and munlockall system calls.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://github.com/torvalds/linux/commit/70feee0e1ef331b22cc51f383d532a0d043fbdcc | third party advisory patch |
https://usn.ubuntu.com/3655-1/ | vendor advisory |
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=70feee0e1ef331b22cc51f383d532a0d043fbdcc | patch vendor advisory |
https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.11.4 | release notes vendor advisory |
https://usn.ubuntu.com/3655-2/ | vendor advisory |
http://www.securityfocus.com/bid/103321 | vdb entry third party advisory |