The cgroup offline implementation in the Linux kernel through 4.8.11 mishandles certain drain operations, which allows local users to cause a denial of service (system hang) by leveraging access to a container environment for executing a crafted application, as demonstrated by trinity.
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"307947450719488514380153899581133893881",
"98919871932645375800480118087709016822",
"95441706484990628671054755255344054771",
"301657393613407546359133189817045336232",
"93098907697801866357819952409659882997",
"28826823528532426920103310229048809252",
"231179267511792454422311244247127955724",
"319119299931760514849833964334475670198"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@93362fa47fe98b62e4a34ab408c4a418432e7939",
"deprecated": false,
"id": "CVE-2016-9191-84e9f980",
"signature_type": "Line",
"target": {
"file": "fs/proc/proc_sysctl.c"
},
"signature_version": "v1"
},
{
"digest": {
"length": 527.0,
"function_hash": "289290355740924534666024466275814250224"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@93362fa47fe98b62e4a34ab408c4a418432e7939",
"deprecated": false,
"id": "CVE-2016-9191-8c4cba24",
"signature_type": "Function",
"target": {
"function": "proc_sys_readdir",
"file": "fs/proc/proc_sysctl.c"
},
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-9191.json"
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"307947450719488514380153899581133893881",
"98919871932645375800480118087709016822",
"95441706484990628671054755255344054771",
"301657393613407546359133189817045336232",
"93098907697801866357819952409659882997",
"28826823528532426920103310229048809252",
"231179267511792454422311244247127955724",
"319119299931760514849833964334475670198"
]
},
"source": "https://github.com/torvalds/linux/commit/93362fa47fe98b62e4a34ab408c4a418432e7939",
"deprecated": false,
"id": "CVE-2016-9191-658da828",
"signature_type": "Line",
"target": {
"file": "fs/proc/proc_sysctl.c"
},
"signature_version": "v1"
},
{
"digest": {
"length": 527.0,
"function_hash": "289290355740924534666024466275814250224"
},
"source": "https://github.com/torvalds/linux/commit/93362fa47fe98b62e4a34ab408c4a418432e7939",
"deprecated": false,
"id": "CVE-2016-9191-8a1f91d4",
"signature_type": "Function",
"target": {
"function": "proc_sys_readdir",
"file": "fs/proc/proc_sysctl.c"
},
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-9191.json"