CVE-2016-10723

MEDIUM

Linux Kernel < 4.17.2 - Denial of Service via OOM Killer CPU Resource Exhaustion

Title source: llm
STIX 2.1

Description

An issue was discovered in the Linux kernel through 4.17.2. Since the page allocator does not yield CPU resources to the owner of the oom_lock mutex, a local unprivileged user can trivially lock up the system forever by wasting CPU resources from the page allocator (e.g., via concurrent page fault events) when the global OOM killer is invoked. NOTE: the software maintainer has not accepted certain proposed patches, in part because of a viewpoint that "the underlying problem is non-trivial to handle.

References (3)

Core 3
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://patchwork.kernel.org/patch/9842889/
Mailing List, Third Party Advisory x_refsource_misc
https://www.spinics.net/lists/linux-mm/msg117896.html
Issue Tracking, Vendor Advisory x_refsource_misc
https://patchwork.kernel.org/patch/10395909/

Scores

CVSS v3 5.5
EPSS 0.0038
EPSS Percentile 30.6%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-399
Status published
Products (1)
linux/linux_kernel < 4.17.2
Published Jun 21, 2018
Tracked Since Feb 18, 2026