CVE-2016-10723
MEDIUMLinux Kernel < 4.17.2 - Denial of Service via OOM Killer CPU Resource Exhaustion
Title source: llmDescription
An issue was discovered in the Linux kernel through 4.17.2. Since the page allocator does not yield CPU resources to the owner of the oom_lock mutex, a local unprivileged user can trivially lock up the system forever by wasting CPU resources from the page allocator (e.g., via concurrent page fault events) when the global OOM killer is invoked. NOTE: the software maintainer has not accepted certain proposed patches, in part because of a viewpoint that "the underlying problem is non-trivial to handle.
References (3)
Core 3
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://patchwork.kernel.org/patch/9842889/
Mailing List, Third Party Advisory x_refsource_misc
https://www.spinics.net/lists/linux-mm/msg117896.html
Issue Tracking, Vendor Advisory x_refsource_misc
https://patchwork.kernel.org/patch/10395909/
Scores
CVSS v3
5.5
EPSS
0.0038
EPSS Percentile
30.6%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-399
Status
published
Products (1)
linux/linux_kernel
< 4.17.2
Published
Jun 21, 2018
Tracked Since
Feb 18, 2026