Vulnerability Name: | CVE-2016-10905 (CCN-169548) | ||||||||||||||||
Assigned: | 2016-06-10 | ||||||||||||||||
Published: | 2016-06-10 | ||||||||||||||||
Updated: | 2019-09-25 | ||||||||||||||||
Summary: | An issue was discovered in fs/gfs2/rgrp.c in the Linux kernel before 4.8. A use-after-free is caused by the functions gfs2_clear_rgrpd and read_rindex_entry. | ||||||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.1 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||
CVSS v2 Severity: | 6.1 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:C)
| ||||||||||||||||
Vulnerability Type: | CWE-416 | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-10905 Source: MISC Type: UNKNOWN http://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.html Source: MISC Type: UNKNOWN http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html Source: CCN Type: The Linux Kernel Archives Web site The Linux Kernel Archives Source: XF Type: UNKNOWN linux-kernel-cve201610905-priv-esc(169548) Source: MISC Type: Patch, Vendor Advisory https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=36e4ad0316c017d5b271378ed9a1c9a4b77fab5f Source: CCN Type: Linux GitHub repository GFS2: don't set rgrp gl_object until it's inserted into rgrp tree Source: CCN Type: Debian Mailing Lists [SECURITY] [DLA 1930-1] linux security update Source: MLIST Type: UNKNOWN [debian-lts-announce] 20190925 [SECURITY] [DLA 1930-1] linux security update Source: BUGTRAQ Type: UNKNOWN 20191108 [slackware-security] Slackware 14.2 kernel (SSA:2019-311-01) Source: CONFIRM Type: UNKNOWN https://support.f5.com/csp/article/K31332013 Source: CONFIRM Type: UNKNOWN https://support.f5.com/csp/article/K31332013?utm_source=f5support&utm_medium=RSS Source: CCN Type: Ubuntu serurity notices USN-4145-1: Linux kernel vulnerabilities Source: UBUNTU Type: UNKNOWN USN-4145-1 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |