Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The epoll_ctl system call in fs/eventpoll.c in the Linux kernel before 3.2.24 does not properly handle ELOOP errors in EPOLL_CTL_ADD operations, which allows local users to cause a denial of service (file-descriptor consumption and system crash) via a crafted application that attempts to create a circular epoll dependency. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1083.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Linux kernel 安全漏洞
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 3.2.24之前版本存在安全漏洞,该漏洞源于未正确处理EPOLL_CTL_ADD操作中的ELOOP错误。本地攻击者利用该漏洞通过特制尝试创建一个圆形的epoll的依赖关系的应用程序,导致拒绝服务(文件描述符消耗和系统崩溃)。
CVSS Information
N/A
Vulnerability Type
N/A