PT-2016-5026 · Linux+3 · Linux Kernel+3

Marcin Kościelnicki

·

Published

2016-04-12

·

Updated

2024-03-14

·

CVE-2016-2143

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.5 on s390 platforms
Description The fork implementation in the Linux kernel mishandles the case of four page-table levels, allowing local users to cause a denial of service (system crash) or possibly have unspecified other impact via a crafted application. This issue is related to arch/s390/include/asm/mmu context.h and arch/s390/include/asm/pgalloc.h.
Recommendations For Linux kernel versions prior to 4.5 on s390 platforms, update to version 4.5 or later to resolve the issue. As a temporary workaround, consider restricting access to crafted applications that could exploit this issue until a patch is available.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2016_1539
CESA-2016_2766
CVE-2016-2143
DLA-516-1
DSA-3607-1
MGASA-2016-0225
MGASA-2016-0232
MGASA-2016-0233
RHSA-2016:1539
RHSA-2016:2766
RHSA-2016_1539
RHSA-2016_2766
SUSE-SU-2016:1019-1
SUSE-SU-2016:1203-1
SUSE-SU-2016:1672-1
SUSE-SU-2016:1690-1
SUSE-SU-2016:1707-1
SUSE-SU-2016:1764-1
SUSE-SU-2016:2074-1

Affected Products

Centos
Linux Kernel
Red Hat
Suse