First published: Mon Nov 21 2016(Updated: )
A flaw was found in the Linux kernels implementation of XFS file attributes. Two memory leaks were detected in xfs_attr_shortform_list and xfs_attr3_leaf_list_int when running a docker container backed by xfs/overlay2. A dedicated attacker could possible exhaust all memory and create a denial of service situation. Product bug: <a class="bz_bug_link bz_secure " title="" href="show_bug.cgi?id=1391223">https://bugzilla.redhat.com/show_bug.cgi?id=1391223</a> OSS-Security post: <a href="http://seclists.org/oss-sec/2016/q4/544">http://seclists.org/oss-sec/2016/q4/544</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | <=4.5.0 | |
debian/linux | 5.10.223-1 5.10.234-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.17-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Multiple memory leaks in error paths in fs/xfs/xfs_attr_list.c in the Linux kernel before 4.5.1 allow local users to cause a denial of service (memory consumption) via crafted XFS filesystem operations.
The vulnerability affects Linux kernel versions before 4.5.1.
The severity of CVE-2016-9685 is low.
To fix CVE-2016-9685, update your Linux kernel to version 4.5.1 or later.
You can find more information about CVE-2016-9685 at the following references: [Link 1](http://www.openwall.com/lists/oss-security/2016/11/30/1), [Link 2](http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2e83b79b2d6c78bf1b4aa227938a214dcbddc83f), [Link 3](http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.1).