The fuse_fill_write_pages function in fs/fuse/file.c in the Linux kernel before 4.4 allows local users to cause a denial of service (infinite loop) via a writev system call that triggers a zero length for the first segment of an iov.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 4.4-rc4 | 4.4-rc4.x |
| linux / linux_kernel | 4.4-rc3 | 4.4-rc3.x |
| linux / linux_kernel | 4.4-rc2 | 4.4-rc2.x |
| linux / linux_kernel | 4.4-rc1 | 4.4-rc1.x |
| linux / linux_kernel | - | 4.4 |
| suse / linux_enterprise_real_time_extension | 12-sp1 | 12-sp1.x |