CVE-2016-6213: Linux Kernel
Medium severity, CVSS 4.7. EPSS: 0.4% chance of exploitation in the next 30 days.
fs/namespace.c in the Linux kernel before 4.9 does not restrict how many mounts may exist in a mount namespace, which allows local users to cause a denial of service (memory consumption and deadlock) via MS_BIND mount system calls, as demonstrated by a loop that triggers exponential growth in the number of mounts.
Affected products
- Linux Linux Kernel: up to and including 4.8.15
Published 2016-12-28. Last modified 2026-06-17.