PT-2016-2704 · Linux+1 · Linux Kernel+1
Published
2015-06-03
·
Updated
2020-08-06
·
CVE-2016-2063
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 3.x
Description
The issue is caused by a stack-based buffer overflow in the
supply lm input write function of the MSM Thermal driver. This can be exploited by sending a large amount of data through the debugfs interface, potentially allowing an attacker to cause a denial of service or have other unspecified impacts.Recommendations
For Linux kernel version 3.x, consider restricting access to the
debugfs interface to minimize the risk of exploitation until a patch is available.
As a temporary workaround, consider disabling the supply lm input write function in the MSM Thermal driver to prevent potential attacks.Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linux Kernel