CVE-2016-9191: Input Validation
A malicious user who can run an arbitrary image with a non-privileged user in a Container-as-a-service cloud environment could use the exploit to deadlock the container nodes to deny the service for other users.
This is confirmed to affect the latest mainline kernel (4.9-rc3) using this kernel config, http://people.redhat.com/qcai/tmp/config-god-4.9rc2 and as old as v3.17. RHEL 7.3 kernel is not affected.
References:
http://seclists.org/oss-sec/2016/q4/340
Other sources
The cgroup offline implementation in the Linux kernel through 4.8.11 mishandles certain drain operations, which allows local users to cause a denial of service (system hang) by leveraging access to a container environment for executing a crafted application, as demonstrated by trinity.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2016-9191.
What does the CVE-2016-9191 vulnerability affect?
The CVE-2016-9191 vulnerability affects the Linux kernel through version 4.8.11.
How can the CVE-2016-9191 vulnerability be exploited?
The CVE-2016-9191 vulnerability can be exploited by local users who have access to a container environment and execute a crafted application.
What is the severity of the CVE-2016-9191 vulnerability?
The severity of the CVE-2016-9191 vulnerability is medium.
Are there any known remedies for the CVE-2016-9191 vulnerability?
Yes, there are known remedies for the CVE-2016-9191 vulnerability provided by the Ubuntu and Debian sources.