Vulnerability Name: | CVE-2016-5728 (CCN-114476) | ||||||||||||||||||||||||
Assigned: | 2016-04-25 | ||||||||||||||||||||||||
Published: | 2016-04-25 | ||||||||||||||||||||||||
Updated: | 2016-11-28 | ||||||||||||||||||||||||
Summary: | Race condition in the vop_ioctl function in drivers/misc/mic/vop/vop_vringh.c in the MIC VOP driver in the Linux kernel before 4.6.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (memory corruption and system crash) by changing a certain header, aka a "double fetch" vulnerability. | ||||||||||||||||||||||||
CVSS v3 Severity: | 6.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H) 5.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C)
7.3 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 5.4 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:C)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-5728 Source: CCN Type: Linux Kernel GIT Repository misc: mic: Fix for double fetch security bug in VOP driver Source: CONFIRM Type: Vendor Advisory http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=9bf292bfca94694a721449e3fd752493856710f6 Source: DEBIAN Type: UNKNOWN DSA-3616 Source: CONFIRM Type: UNKNOWN http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.6.1 Source: BUGTRAQ Type: UNKNOWN 20160630 [CVE-2016-5728] Double-Fetch Vulnerability in Linux-4.5/drivers/misc/mic/host/mic_virtio.c Source: CCN Type: BID-91477 Linux Kernel CVE-2016-5728 Local Race Condition Vulnerability Source: UBUNTU Type: UNKNOWN USN-3070-1 Source: UBUNTU Type: UNKNOWN USN-3070-2 Source: UBUNTU Type: UNKNOWN USN-3070-3 Source: UBUNTU Type: UNKNOWN USN-3070-4 Source: UBUNTU Type: UNKNOWN USN-3071-1 Source: UBUNTU Type: UNKNOWN USN-3071-2 Source: CCN Type: Kernel Bug Tracker Bug 116651 Double-Fetch bug in Linux-4.5/drivers/misc/mic/host/mic_virtio.c Source: CONFIRM Type: UNKNOWN https://bugzilla.kernel.org/show_bug.cgi?id=116651 Source: XF Type: UNKNOWN linux-cve20165728-dos(114476) Source: CONFIRM Type: Vendor Advisory https://github.com/torvalds/linux/commit/9bf292bfca94694a721449e3fd752493856710f6 Source: CCN Type: WhiteSource Vulnerability Database CVE-2016-5728 | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |