CVE-2000-0456: Low severity NetBSD NetBSD vulnerability
NetBSD 1.4.2 and earlier allows local users to cause a denial of service by repeatedly running certain system calls in the kernel which do not yield the CPU, aka "cpu-hog".
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure per-user or per-process CPU/time limits (via shell ulimit, login class, or system login configuration) to prevent processes from consuming CPU indefinitely.
system resource limits (login/shell) per-process CPU time limit = set a reasonable per-process/per-user CPU time limit (e.g., ulimit -t or equivalent login-class limits) - Compensating control
Restrict local interactive access to trusted users only. Disable or remove unneeded local accounts and restrict shell/login access for untrusted accounts so unprivileged users cannot run arbitrary local processes that might trigger the cpu-hog behavior.
- Operational
Deploy monitoring and automated response for high-CPU processes: detect processes that consume excessive CPU or do not yield the CPU and terminate or restart them. Maintain incident procedures to investigate and remediate occurrences of the cpu-hog behavior.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0456?
CVE-2000-0456 has a severity rating that indicates a potential denial of service vulnerability.
How do I fix CVE-2000-0456?
To mitigate CVE-2000-0456, it is recommended to upgrade to a newer version of NetBSD that is not affected by this vulnerability.
Who is affected by CVE-2000-0456?
Local users on NetBSD versions 1.4.1 and 1.4.2 are vulnerable to CVE-2000-0456.
What type of vulnerability is CVE-2000-0456?
CVE-2000-0456 is classified as a denial of service vulnerability affecting the NetBSD operating system.
What versions of NetBSD are impacted by CVE-2000-0456?
CVE-2000-0456 affects NetBSD versions 1.4.1 and 1.4.2.