Bug 988964 (CVE-2016-6213) - VUL-1: CVE-2016-6213: kernel-source: Overflowing kernel mount table using shared bind mount
Summary: VUL-1: CVE-2016-6213: kernel-source: Overflowing kernel mount table using sha...
Status: RESOLVED FIXED
Alias: CVE-2016-6213
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Minor
Target Milestone: ---
Assignee: Goldwyn Rodrigues
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/170928/
Whiteboard: CVSSv2:SUSE:CVE-2016-6213:4.0:(AV:L/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-07-14 13:18 UTC by Andreas Stieger
Modified: 2020-06-11 12:18 UTC (History)
6 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2016-07-14 13:18:25 UTC
from http://seclists.org/oss-sec/2016/q3/58


    It was reported that the mount table expands by a power-of-two
    with each bind mount command.


    If the system is configured in the way that a non-root user
    allows bind mount even if with limit number of bind mount
    allowed, a non-root user could cause a local DoS by quickly
    overflow the mount table.


    it will cause a deadlock for the whole system,


        form of unlimited memory consumption that is causing the problem


Use CVE-2016-6213.




Not clear if an improperly configured system warrants a CVE or a fix.


References:
https://bugzilla.redhat.com/show_bug.cgi?id=1356471
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-6213
http://seclists.org/oss-sec/2016/q3/58
Comment 2 Swamp Workflow Management 2016-07-14 22:00:25 UTC
bugbot adjusting priority
Comment 3 Joerg Roedel 2016-07-20 08:43:21 UTC
Adding needinfo
Comment 4 Jeff Mahoney 2016-07-20 09:37:14 UTC
My opinion on this falls between calling it a CVE and GregKH's "not-a-bug" response.  Yeah, it's a stupid configuration but stupid configurations shouldn't soft lockup the kernel.

Goldwyn, here's an actual VFS bug for you. :)
Comment 6 Marcus Meissner 2017-07-04 12:57:13 UTC
any idea on how to proceed?
Comment 7 Goldwyn Rodrigues 2017-07-06 01:16:02 UTC
openSUSE 42.2, SLE12-SP2/SP3 is covered by (backported):
c50fd34e1089 ("mnt: Add a per mount namespace limit on the number of mounts")
Comment 8 Marcus Meissner 2018-02-09 06:17:44 UTC
fixed in newer productgs.