Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-6001

Опубликовано: 18 фев. 2017
Источник: debian
EPSS Низкий

Описание

Race condition in kernel/events/core.c in the Linux kernel before 4.9.7 allows local users to gain privileges via a crafted application that makes concurrent perf_event_open system calls for moving a software group into a hardware context. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-6786.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed4.9.10-1package

Примечания

  • Fixed by: https://git.kernel.org/linus/321027c1fe77f892f4ea07846aeae08cefbbb290

EPSS

Процентиль: 31%
0.00115
Низкий

Связанные уязвимости

CVSS3: 7
ubuntu
больше 8 лет назад

Race condition in kernel/events/core.c in the Linux kernel before 4.9.7 allows local users to gain privileges via a crafted application that makes concurrent perf_event_open system calls for moving a software group into a hardware context. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-6786.

CVSS3: 7
redhat
больше 8 лет назад

Race condition in kernel/events/core.c in the Linux kernel before 4.9.7 allows local users to gain privileges via a crafted application that makes concurrent perf_event_open system calls for moving a software group into a hardware context. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-6786.

CVSS3: 7
nvd
больше 8 лет назад

Race condition in kernel/events/core.c in the Linux kernel before 4.9.7 allows local users to gain privileges via a crafted application that makes concurrent perf_event_open system calls for moving a software group into a hardware context. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-6786.

CVSS3: 7
github
около 3 лет назад

Race condition in kernel/events/core.c in the Linux kernel before 4.9.7 allows local users to gain privileges via a crafted application that makes concurrent perf_event_open system calls for moving a software group into a hardware context. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-6786.

CVSS3: 7.5
fstec
больше 8 лет назад

Уязвимость компонента kernel/events/core.c ядра операционной системы, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 31%
0.00115
Низкий