A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffer in a specific way. Only privileged local users (with CAP_SYS_ADMIN capability) could use this flaw to starve the resources causing denial of service.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 5.14-rc1 | 5.14-rc1.x |
| linux / linux_kernel | 5.14-rc2 | 5.14-rc2.x |
| linux / linux_kernel | 5.14 | 5.14.x |
| linux / linux_kernel | - | 5.14 |
| redhat / enterprise_linux | 8.0 | 8.0.x |
| debian / debian_linux | 9.0 | 9.0.x |
| debian / debian_linux | 10.0 | 10.0.x |