vulnerability
Ubuntu: (CVE-2016-9576): linux vulnerability
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:L/AC:L/Au:N/C:C/I:C/A:C) | Dec 28, 2016 | Nov 19, 2024 | Sep 1, 2025 |
Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Dec 28, 2016
Added
Nov 19, 2024
Modified
Sep 1, 2025
Description
The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 4.8.14 does not properly restrict the type of iterator, which allows local users to read or write to arbitrary kernel memory locations or cause a denial of service (use-after-free) by leveraging access to a /dev/sg device.
Solutions
ubuntu-upgrade-linuxubuntu-upgrade-linux-awsubuntu-upgrade-linux-hweubuntu-upgrade-linux-hwe-edgeubuntu-upgrade-linux-lts-xenialubuntu-upgrade-linux-raspi2ubuntu-upgrade-linux-snapdragon
References
- CVE-2016-9576
- https://attackerkb.com/topics/CVE-2016-9576
- CWE-416
- URL-http://www.openwall.com/lists/oss-security/2016/12/08/19
- URL-https://gist.githubusercontent.com/dvyukov/80cd94b4e4c288f16ee4c787d404118b/raw/10536069562444da51b758bb39655b514ff93b45/gistfile1.txt
- URL-https://github.com/torvalds/linux/commit/86db1e29772372155db08ff48a9ceb76e11a2ad1
- URL-https://marc.info/?l=linux-scsi&m=148010092224801&w=2
- URL-https://www.cve.org/CVERecord?id=CVE-2016-9576
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.