PT-2016-7426 · Linux+3 · Linux Kernel+3

Dmitry Vyukov

·

Published

2016-08-15

·

Updated

2023-01-19

·

CVE-2016-7911

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.6.6
Description A race condition exists in the get task ioprio function, allowing local users to potentially gain privileges or cause a denial of service through a crafted ioprio get system call. This issue can lead to a use-after-free scenario.
Recommendations For Linux kernel versions prior to 4.6.6, update to version 4.6.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the ioprio get system call to minimize the risk of exploitation.

Fix

DoS

Race Condition

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1842
ALT-PU-2016-1843
CVE-2016-7911
DLA-772-1
OPENSUSE-SU-2016_3061-1
SUSE-SU-2017:0333-1
SUSE-SU-2017:0407-1
SUSE-SU-2017:0437-1
SUSE-SU-2017:0464-1
SUSE-SU-2017:0471-1
SUSE-SU-2017:0494-1
SUSE-SU-2017:1102-1
USN-3206-1
USN-3207-1
USN-3207-2

Affected Products

Alt Linux
Linux Kernel
Suse
Ubuntu