CVE-2015-4170

Description

A flaw was discovered in the way the Linux kernel's TTY subsystem handled the tty shutdown phase. A local, unprivileged user could use this flaw to cause denial of service on the system by holding a reference to the ldisc lock during tty shutdown, causing a deadlock.

Déclaration

This issue does not affect the Linux kernels as shipped with Red Hat Enterprise Linux 5, 6.

This issue affects the Linux kernel packages kernel as shipped with Red Hat Enterprise Linux 7 and Red Hat Enterprise MRG 2.

Détails du score du système commun d'évaluation des vulnérabilités (CVSS)

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

Répartition des scores CVSS v2

Red HatNVDcve.org
Score de base4.74.7N/A
Vecteur d'attaqueLocalLocalN/A
Complexité d'accèsMediumMediumN/A
AuthentificationNoneNoneN/A
Impact sur la confidentialitéNoneNoneN/A
Impact sur l'intégritéNoneNoneN/A
Impact sur la disponibilitéCompleteCompleteN/A

Vecteur

Red Hat: AV:L/AC:M/Au:N/C:N/I:N/A:C

NVD: AV:L/AC:M/Au:N/C:N/I:N/A:C

Comprendre la Défaillance (CWE)

Availability

Technical Impact: DoS: Resource Consumption (CPU)

Inconsistent locking discipline can lead to deadlock.

Questions fréquemment posées

Vous souhaitez recevoir des notifications d'errata ? Signez ici.