The cgroup offline implementation in the Linux kernel through 4.8.11 mishandles certain drain operations, which allows local users to cause a denial of service (system hang) by leveraging access to a container environment for executing a crafted application, as demonstrated by trinity.
Product | Vendor | Version |
---|---|---|
n/a | n/a | < 801ea33ae82d6a9d954074fbcf8ea9d18f1543a7 |