CVE-2016-2847: Medium severity linux kernel vulnerability

Published Mar 1, 2016
·
Updated

fs/pipe.c in the Linux kernel before 4.5 does not limit the amount of unread data in pipes, which allows local users to cause a denial of service (memory consumption) by creating many pipes with non-default sizes.

Other sources

On no-so-small systems, it is possible for a single process to cause an OOM condition by filling large pipes with data that are never read. A typical process filling 4096 pipes with 1 MB of data will use 4 GB of memory. On small systems it may be tricky to set the pipe max size to prevent this from happening. The result is an OOM condition and oom-killer is not able to help much, as the memory for the pipe data is a kernel memory and a memory footprint of offensive processes is small.

Upstream patch: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=759c01142a5d0f364a462346168a56de28a80f52

Discussion threads: https://www.spinics.net/lists/linux-fsdevel/msg92912.html | https://lkml.org/lkml/2015/12/28/150 https://www.spinics.net/lists/linux-fsdevel/msg93317.html | https://lkml.org/lkml/2016/1/11/310 https://www.spinics.net/lists/linux-fsdevel/msg93601.html | https://lkml.org/lkml/2016/1/18/171

CVE request and assignment: http://seclists.org/oss-sec/2016/q1/467 http://seclists.org/oss-sec/2016/q1/538

Red Hat

Affected Software

18 affected componentsFixes available
Linux Linux kernel<=4.4.8
Novell Suse Linux Enterprise Software Development Kit=11.0-sp4
Novell Suse Linux Enterprise Software Development Kit=12.0
Novell Suse Linux Enterprise Software Development Kit=12.0-sp1
Novell Suse Linux Enterprise Debuginfo=11.0-sp4
Novell Suse Linux Enterprise Desktop=12.0
Novell Suse Linux Enterprise Desktop=12.0-sp1
Novell Suse Linux Enterprise Live Patching=12.0
Novell Suse Linux Enterprise Module For Public Cloud=12.0
Novell Suse Linux Enterprise Real Time Extension=11.0-sp4
Novell Suse Linux Enterprise Real Time Extension=12.0-sp1
Novell Suse Linux Enterprise Server=11.0-extra
Novell Suse Linux Enterprise Server=11.0-sp4
Novell Suse Linux Enterprise Server=12.0
Novell Suse Linux Enterprise Server=12.0-sp1
Novell Suse Linux Enterprise Workstation Extension=12.0
Novell Suse Linux Enterprise Workstation Extension=12.0-sp1
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.22-16.12.25-1

Event History

Mar 1, 2016
Data Sourced
via Red Hat·03:22 PM
DescriptionSeverityAffected Software
Apr 27, 2016
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:17 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:14 AM
RemedyDescriptionSeverityAffected Software
Apr 28, 2025
Data Sourced
via Debian·03:28 AM
DescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2016-2847?

CVE-2016-2847 has a severity rating that indicates it can lead to denial of service by consuming excessive memory.

2

How do I fix CVE-2016-2847?

To fix CVE-2016-2847, update the Linux kernel to version 4.5 or later, or apply the relevant patches provided by your distribution.

3

Which versions of Linux are affected by CVE-2016-2847?

CVE-2016-2847 affects Linux kernel versions before 4.5, as well as specific versions of SUSE Linux Enterprise products.

4

What is the impact of CVE-2016-2847?

The impact of CVE-2016-2847 includes the potential for local users to create a denial of service through high memory consumption.

5

Who can exploit CVE-2016-2847?

CVE-2016-2847 can be exploited by local users on the system, as it does not require remote access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203