First published: Wed Feb 24 2016(Updated: )
Function hrtimer_cancel() waits for the completion from the callback, thus it must not be called inside the callback itself. This was already a problem in the past with ALSA hrtimer driver, and the early commit [fcfdebe70759: ALSA: hrtimer - Fix lock-up] tried to address it. Upstream patch: <a href="http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2ba1fe7a06d3624f9a7586d672b55f08f7c670f3">http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2ba1fe7a06d3624f9a7586d672b55f08f7c670f3</a> Original report: <a href="http://marc.info/?l=linux-kernel&m=145271261602328">http://marc.info/?l=linux-kernel&m=145271261602328</a> <a href="http://marc.info/?l=linux-kernel&m=145288522219596">http://marc.info/?l=linux-kernel&m=145288522219596</a> <a href="http://marc.info/?t=145269725600010&r=1&w=2">http://marc.info/?t=145269725600010&r=1&w=2</a> CVE-ID request and assignment: <a href="http://seclists.org/oss-sec/2016/q1/133">http://seclists.org/oss-sec/2016/q1/133</a> <a href="http://seclists.org/oss-sec/2016/q1/410">http://seclists.org/oss-sec/2016/q1/410</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | <=4.4 | |
debian/linux | 5.10.223-1 5.10.226-1 6.1.115-1 6.1.119-1 6.11.10-1 6.12.5-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-2549 is low.
CVE-2016-2549 allows local users to cause a denial of service (deadlock) through a crafted ioctl call.
To fix CVE-2016-2549 on Ubuntu, you need to update to Linux kernel version 3.2.0-102.142 or later.
More information about CVE-2016-2549 can be found in the references: [link](http://www.openwall.com/lists/oss-security/2016/01/19/1), [link](http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2ba1fe7a06d3624f9a7586d672b55f08f7c670f3), [link](http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.1).
The affected software for CVE-2016-2549 includes Ubuntu Linux with kernel versions 3.2.0-102.142 to 4.4.1.