| Vulnerability Name: | CVE-2016-6156 (CCN-114718) | ||||||||||||||||||||
| Assigned: | 2016-07-04 | ||||||||||||||||||||
| Published: | 2016-07-04 | ||||||||||||||||||||
| Updated: | 2016-11-28 | ||||||||||||||||||||
| Summary: | Race condition in the ec_device_ioctl_xcmd function in drivers/platform/chrome/cros_ec_dev.c in the Linux kernel before 4.7 allows local users to cause a denial of service (out-of-bounds array access) by changing a certain size value, aka a "double fetch" vulnerability. | ||||||||||||||||||||
| CVSS v3 Severity: | 5.1 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H) 4.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||||||
| CVSS v2 Severity: | 1.9 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P)
| ||||||||||||||||||||
| Vulnerability Type: | CWE-362 | ||||||||||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2016-6156 Source: CONFIRM Type: Issue Tracking, Patch http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=096cdc6f52225835ff503f987a0d68ef770bb78e Source: BUGTRAQ Type: Third Party Advisory, VDB Entry 20160704 [CVE-2016-6156] Double-Fetch Vulnerability in Linux-4.6/drivers/platform/chrome/cros_ec_dev.c Source: CCN Type: BugTraq Mailing List, Mon, 4 Jul 2016 12:48:13 GMT [CVE-2016-6156] Double-Fetch Vulnerability in Linux-4.6/drivers/platform/chrome/cros_ec_dev.c Source: BID Type: UNKNOWN 91553 Source: CCN Type: BID-91553 Linux Kernel CVE-2016-6156 Local Information Disclosure Vulnerability Source: CCN Type: Kernel Bug Tracker Bug 120131 Double-Fetch bug in Linux-4.6/drivers/platform/chrome/cros_ec_dev.c Source: MISC Type: Issue Tracking https://bugzilla.kernel.org/show_bug.cgi?id=120131 Source: CONFIRM Type: Issue Tracking https://bugzilla.redhat.com/show_bug.cgi?id=1353490 Source: XF Type: UNKNOWN linux-kernel-cve20166156-bo(114718) Source: CONFIRM Type: Issue Tracking, Patch https://github.com/torvalds/linux/commit/096cdc6f52225835ff503f987a0d68ef770bb78e Source: CCN Type: WhiteSource Vulnerability Database CVE-2016-6156 | ||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
| BACK | |||||||||||||||||||||