4.7
CVSSv2

CVE-2016-7916

Published: 16/11/2016 Updated: 18/01/2017
CVSS v2 Base Score: 4.7 | Impact Score: 6.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 419
Vector: AV:L/AC:M/Au:N/C:C/I:N/A:N

Vulnerability Summary

Race condition in the environ_read function in fs/proc/base.c in the Linux kernel prior to 4.5.4 allows local users to obtain sensitive information from kernel memory by reading a /proc/*/environ file during a process-setup time interval in which environment-variable copying is incomplete.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

Vendor Advisories

The system could be made to expose sensitive information ...
The system could be made to expose sensitive information ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
Race condition in the environ_read() function in 'fs/proc/basec' in the Linux kernel before 454 allows local users to obtain sensitive information from kernel memory by reading a '/proc/*/environ' file during a process-setup time interval in which environment-variable copying is incomplete ...