Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1111180 - (CVE-2014-4171) CVE-2014-4171 Kernel: mm/shmem: denial of service
CVE-2014-4171 Kernel: mm/shmem: denial of service
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20140617,repor...
: Security
Depends On: 1118244 1118245 1118246 1118247
Blocks: 1111112
  Show dependency treegraph
 
Reported: 2014-06-19 08:07 EDT by Prasad J Pandit
Modified: 2015-07-31 03:22 EDT (History)
30 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
A race condition flaw was found in the way the Linux kernel's mmap(2), madvise(2), and fallocate(2) system calls interacted with each other while operating on virtual memory file system files. A local user could use this flaw to cause a denial of service.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-01-28 15:12:51 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2014:1318 normal SHIPPED_LIVE Moderate: Red Hat Enterprise MRG Realtime 2.5 security and enhancement update 2014-09-29 19:41:06 EDT
Red Hat Product Errata RHSA-2015:0102 normal SHIPPED_LIVE Important: kernel security and bug fix update 2015-01-28 19:02:51 EST

  None (edit)
Description Prasad J Pandit 2014-06-19 08:07:33 EDT
Linux kernel built with the shared memory support is vulnerable to a denial of service flaw caused by a race condition in mmap access to a hole, while it is punched from shmem and madvise(2) & fallocate(2) calls. In that mmap access could prevent the other calls from completing.

A user/process could use this flaw to cause a DoS.

Upstream fixes:
-------------
  -> https://git.kernel.org/linus/f00cdc6df7d7cfcabb5b740911e6788cb0802bdb
  -> https://git.kernel.org/linus/8e205f779d1443a94b5ae81aa359cb535dd3021e
  -> https://git.kernel.org/linus/b1a366500bd537b50c3aad26dc7df083ec03a448

Reference:
----------
  -> http://www.openwall.com/lists/oss-security/2014/06/18/11
Comment 1 Prasad J Pandit 2014-07-10 05:41:43 EDT
Statement:

This issue does not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6.

This issue affects the version of the kernel package as shipped with Red Hat Enterprise Linux 7 and Red Hat Enterprise MRG 2. Future kernel updates for Red Hat Enterprise Linux 7 and Red Hat Enterprise MRG 2 may address this issue.
Comment 4 Prasad J Pandit 2014-07-10 05:44:16 EDT
Created kernel tracking bugs for this issue:

Affects: fedora-all [bug 1118247]
Comment 9 Fedora Update System 2014-08-01 02:02:41 EDT
kernel-3.15.7-200.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 10 Fedora Update System 2014-08-08 04:41:48 EDT
kernel-3.14.15-100.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 12 errata-xmlrpc 2014-09-29 15:41:34 EDT
This issue has been addressed in the following products:

  MRG for RHEL-6 v.2

Via RHSA-2014:1318 https://rhn.redhat.com/errata/RHSA-2014-1318.html
Comment 13 Martin Prpič 2014-09-30 06:48:03 EDT
IssueDescription:

A race condition flaw was found in the way the Linux kernel's mmap(2), madvise(2), and fallocate(2) system calls interacted with each other while operating on virtual memory file system files. A local user could use this flaw to cause a denial of service.
Comment 14 errata-xmlrpc 2015-01-28 14:03:41 EST
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2015:0102 https://rhn.redhat.com/errata/RHSA-2015-0102.html

Note You need to log in before you can comment on or make changes to this bug.