PT-2016-4389 · Linux+4 · Linux Kernel+4

Adam Mariš

·

Publicado

2016-01-19

·

Atualizado

2024-06-15

·

CVE-2016-0723

CVSS v3.1

6.8

Média

VetorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.4.1
Description A race condition in the tty ioctl function in drivers/tty/tty io.c may allow local users to obtain sensitive information from kernel memory or cause a denial of service, such as a use-after-free condition and system crash, by making a TIOCGETD ioctl call during processing of a TIOCSETD ioctl call.
Recommendations For Linux kernel versions prior to 4.4.1, update to version 4.4.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the tty ioctl function to minimize the risk of exploitation.

Correção

DoS

Race Condition

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1137
ALT-PU-2016-1485
CVE-2016-0723
DLA-412-1
DSA-3448-1
DSA-3503-1
OPENSUSE-SU-2016_0537-1
OPENSUSE-SU-2016_1008-1
OPENSUSE-SU-2024:10128-1
SUSE-SU-2016:0585-1
SUSE-SU-2016:0785-1
SUSE-SU-2016:0911-1
SUSE-SU-2016:1102-1
SUSE-SU-2016:1203-1
SUSE-SU-2016:1764-1
SUSE-SU-2016:2074-1
USN-2929-1
USN-2929-2
USN-2930-1
USN-2930-2
USN-2930-3
USN-2932-1
USN-2948-1
USN-2948-2
USN-2967-1
USN-2967-2

Produtos afetados

Alt Linux
Fortios
Linux Kernel
Suse
Ubuntu