CVE Vulnerabilities

CVE-2015-8785

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Feb 08, 2016 | Modified: Jan 31, 2022
CVSS 3.x
6.2
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4.9 MEDIUM
AV:L/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu

The fuse_fill_write_pages function in fs/fuse/file.c in the Linux kernel before 4.4 allows local users to cause a denial of service (infinite loop) via a writev system call that triggers a zero length for the first segment of an iov.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Linux_kernel Linux 4.4 4.4
Linux_kernel Linux 4.4 4.4
Linux_kernel Linux 4.4 4.4
Linux_kernel Linux 4.4 4.4
Linux_kernel Linux * *

References