PT-2016-5196 · Linux+3 · Linux Kernel+3

Dmitry Vyukov

·

Published

2016-01-13

·

Updated

2017-09-07

·

CVE-2016-2544

CVSS v3.1

5.1

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.4.1
Description The issue is related to a race condition in the queue delete function, which can be exploited by local users to cause a denial of service. This can result in a use-after-free condition and potentially crash the system. The exploitation is possible by making an ioctl call at a specific time.
Recommendations For versions prior to 4.4.1, update to version 4.4.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the queue delete function in the sound/core/seq/seq queue.c module to minimize the risk of exploitation.

Fix

DoS

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1018
ALT-PU-2016-1485
CVE-2016-2544
DSA-3503-1
OPENSUSE-SU-2016_2144-1
SUSE-SU-2016:0911-1
SUSE-SU-2016:1102-1
SUSE-SU-2016:1203-1
SUSE-SU-2016:2074-1
USN-2929-1
USN-2929-2
USN-2930-1
USN-2930-2
USN-2930-3
USN-2931-1
USN-2932-1
USN-2967-1
USN-2967-2

Affected Products

Alt Linux
Linux Kernel
Suse
Ubuntu