The Linux Kernel versions 4.14, 4.15, and 4.16 has a...
Vulnerability Description
The Linux Kernel versions 4.14, 4.15, and 4.16 has a null pointer dereference which can result in an out of memory (OOM) killing of large mlocked processes. The issue arises from an oom killed process's final thread calling exit_mmap(), which calls munlock_vma_pages_all() for mlocked vmas.This can happen synchronously with the oom reaper's unmap_page_range() since the vma's VM_LOCKED bit is cleared before munlocking (to determine if any other vmas share the memory and are mlocked).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-1000200
Credits & Attribution
No credits recorded in the NVD database.
References
- https://usn.ubuntu.com/3752-2/
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=27ae357fa82be5ab73b2ef8d39dcb8ca2563483a
- https://usn.ubuntu.com/3752-3/
- https://access.redhat.com/security/cve/cve-2018-1000200
- https://marc.info/?l=linux-kernel&m=152460926619256
- https://access.redhat.com/errata/RHSA-2018:2948
- http://www.securityfocus.com/bid/104397
- https://marc.info/?l=linux-kernel&m=152400522806945
- https://usn.ubuntu.com/3752-1/
- http://seclists.org/oss-sec/2018/q2/67
More from linux
View All →Affected Vendor
linux
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.