CVE-2016-10723
Summary
| CVE | CVE-2016-10723 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-21 13:29:00 UTC |
| Updated | 2023-11-07 02:29:00 UTC |
| Description | ** DISPUTED ** An issue was discovered in the Linux kernel through 4.17.2. Since the page allocator does not yield CPU resources to the owner of the oom_lock mutex, a local unprivileged user can trivially lock up the system forever by wasting CPU resources from the page allocator (e.g., via concurrent page fault events) when the global OOM killer is invoked. NOTE: the software maintainer has not accepted certain proposed patches, in part because of a viewpoint that "the underlying problem is non-trivial to handle." |
Risk And Classification
Problem Types: CWE-399
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [PATCH] mm/page_alloc: Wait for oom_lock before retrying. — Linux Memory Management | MISC | www.spinics.net | Mailing List, Third Party Advisory |
| 404: File not found - Patchwork | MISC | patchwork.kernel.org | Issue Tracking, Vendor Advisory |
| mm,oom: Don't call schedule_timeout_killable() with oom_lock held. - Patchwork | MISC | patchwork.kernel.org | Issue Tracking, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.