CVE-2016-2550
MEDIUMLinux Kernel < 4.4.8 - Resource Management Error
Title source: ruleDescription
The Linux kernel before 4.5 allows local users to bypass file-descriptor limits and cause a denial of service (memory consumption) by leveraging incorrect tracking of descriptor ownership and sending each descriptor over a UNIX socket before closing it. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-4312.
References (14)
Scores
CVSS v3
5.5
EPSS
0.0002
EPSS Percentile
5.7%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-399
Status
draft
Affected Products (1)
linux/linux_kernel
< 4.4.8
Timeline
Published
Apr 27, 2016
Tracked Since
Feb 18, 2026