vendor:
Linux Kernel
by:
Google Project Zero
7.5
CVSS
HIGH
Kernel Vulnerability
119
CWE
Product Name: Linux Kernel
Affected Version From: Linux kernel version with 32-bit reference counters
Affected Version To: Linux kernel version with 32-bit reference counters
Patch Exists: NO
Related CWE:
CPE: o:linux:linux_kernel
Platforms Tested: Linux
2018
Kernel Reference Counter Overflow Vulnerability
The vulnerability allows an attacker to create references to BPF programs, which can overflow the 32-bit reference counters in the kernel. By filling approximately 32GB of memory, the overflow can occur, subject to RLIMIT_MEMLOCK restrictions. This can lead to a kernel paging request error and potentially cause a system crash or instability.
Mitigation:
Apply the patch provided by the vendor.