Bug 1999675 (CVE-2021-3759) - CVE-2021-3759 kernel: unaccounted ipc objects in Linux kernel lead to breaking memcg limits and DoS attacks
Summary: CVE-2021-3759 kernel: unaccounted ipc objects in Linux kernel lead to breakin...
Status: NEW
Alias: CVE-2021-3759
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Depends On: 1999705 1999706 1999707
Blocks: 1984846
TreeView+ depends on / blocked
Reported: 2021-08-31 14:39 UTC by Alex
Modified: 2021-09-24 08:30 UTC (History)
39 users (show)

Fixed In Version: Linux kernel 5.15-rc1
Doc Type: If docs needed, set a value
Doc Text:
A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The highest threat from this vulnerability is to system availability.
Clone Of:
Last Closed:

Attachments (Terms of Use)

Description Alex 2021-08-31 14:39:34 UTC
There is a missing-accounting vulnerability in memcg subsystem of Linux kernel, leading to out of memory and then host system crashes because of this.


Note You need to log in before you can comment on or make changes to this bug.