6.8
CVSSv3

CVE-2016-0723

Published: 08/02/2016 Updated: 06/12/2016
CVSS v2 Base Score: 5.6 | Impact Score: 7.8 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.8 | Impact Score: 4.2 | Exploitability Score: 2.5
VMScore: 499
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:C

Vulnerability Summary

Race condition in the tty_ioctl function in drivers/tty/tty_io.c in the Linux kernel up to and including 4.4.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (use-after-free and system crash) by making a TIOCGETD ioctl call during processing of a TIOCSETD ioctl call.

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

Vendor Advisories

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation or denial-of-service CVE-2013-4312 Tetsuo Handa discovered that it is possible for a process to open far more files than the process' limit leading to denial-of-service conditions CVE-2015-7566 Ralf Spenneberg of OpenSource Se ...
The Linux kernel before 441 allows local users to bypass file-descriptor limits and cause a denial of service (memory consumption) by sending each descriptor over a UNIX socket before closing it, related to net/unix/af_unixc and net/unix/garbagec (CVE-2013-4312) A race condition in the tty_ioctl function in drivers/tty/tty_ioc in the Linux ke ...
A use-after-free flaw was discovered in the Linux kernel's tty subsystem, which allows for the disclosure of uncontrolled memory location and possible kernel panic The information leak is caused by a race condition when attempting to set and read the tty line discipline A local attacker could use the TIOCSETD (via tty_set_ldisc ) to switch to a ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
USN 2948-1 introduced a regression in the Ubuntu 1410 Linux kernel backported to Ubuntu 1404 LTS ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...

References

CWE-200CWE-362NVD-CWE-Otherhttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=5c17c861a357e9458001f021a7afa7aab9937439https://github.com/torvalds/linux/commit/5c17c861a357e9458001f021a7afa7aab9937439https://bugzilla.redhat.com/show_bug.cgi?id=1296253https://security-tracker.debian.org/tracker/CVE-2016-0723http://source.android.com/security/bulletin/2016-07-01.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttp://www.securityfocus.com/bid/82950http://www.debian.org/security/2016/dsa-3503http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.htmlhttp://www.ubuntu.com/usn/USN-2967-1http://www.ubuntu.com/usn/USN-2967-2http://www.ubuntu.com/usn/USN-2930-1http://www.ubuntu.com/usn/USN-2929-1http://www.ubuntu.com/usn/USN-2932-1http://www.ubuntu.com/usn/USN-2948-2http://www.securitytracker.com/id/1035695http://www.ubuntu.com/usn/USN-2930-2http://www.ubuntu.com/usn/USN-2929-2http://www.ubuntu.com/usn/USN-2930-3http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.htmlhttp://www.ubuntu.com/usn/USN-2948-1http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176484.htmlhttp://www.debian.org/security/2016/dsa-3448http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176464.htmlhttps://support.f5.com/csp/article/K43650115https://nvd.nist.govhttps://www.debian.org/security/./dsa-3448https://usn.ubuntu.com/2967-1/