Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-9576

Опубликовано: 28 дек. 2016
Источник: debian
EPSS Низкий

Описание

The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 4.8.14 does not properly restrict the type of iterator, which allows local users to read or write to arbitrary kernel memory locations or cause a denial of service (use-after-free) by leveraging access to a /dev/sg device.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed4.8.15-1package
linuxfixed3.16.39-1jessiepackage

Примечания

  • https://marc.info/?l=linux-scsi&m=148010092224801&w=2

  • https://gist.githubusercontent.com/dvyukov/80cd94b4e4c288f16ee4c787d404118b/raw/10536069562444da51b758bb39655b514ff93b45/gistfile1.txt

  • Fixed by: https://git.kernel.org/linus/a0ac402cfcdc904f9772e1762b3fda112dcc56a0 (v4.9)

EPSS

Процентиль: 21%
0.00067
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 8 лет назад

The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 4.8.14 does not properly restrict the type of iterator, which allows local users to read or write to arbitrary kernel memory locations or cause a denial of service (use-after-free) by leveraging access to a /dev/sg device.

CVSS3: 7
redhat
больше 8 лет назад

The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 4.8.14 does not properly restrict the type of iterator, which allows local users to read or write to arbitrary kernel memory locations or cause a denial of service (use-after-free) by leveraging access to a /dev/sg device.

CVSS3: 7.8
nvd
больше 8 лет назад

The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 4.8.14 does not properly restrict the type of iterator, which allows local users to read or write to arbitrary kernel memory locations or cause a denial of service (use-after-free) by leveraging access to a /dev/sg device.

suse-cvrf
больше 8 лет назад

Security update for the openSUSE Leap 42.1 kernel.

suse-cvrf
больше 8 лет назад

Security update for the Linux Kernel

EPSS

Процентиль: 21%
0.00067
Низкий