Lucene search

K
cve[email protected]CVE-2016-1583
HistoryJun 27, 2016 - 10:59 a.m.

CVE-2016-1583

2016-06-2710:59:03
CWE-119
web.nvd.nist.gov
227
ecryptfs
privileged open
linux kernel
cve-2016-1583
security
denial of service
nvd
memory consumption
stack
mmap
proc
pagefault

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.8%

The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted mmap calls for /proc pathnames, leading to recursive pagefault handling.

Affected configurations

NVD
Node
linuxlinux_kernelRange2.6.193.18.54
OR
linuxlinux_kernelRange3.194.4.14
OR
linuxlinux_kernelRange4.54.6.3
Node
novellsuse_linux_enterprise_software_development_kitMatch11.0sp4
OR
novellsuse_linux_enterprise_software_development_kitMatch12.0
OR
novellsuse_linux_enterprise_software_development_kitMatch12.0sp1
OR
novellsuse_linux_enterprise_debuginfoMatch11.0sp4
OR
novellsuse_linux_enterprise_desktopMatch12.0
OR
novellsuse_linux_enterprise_desktopMatch12.0sp1
OR
novellsuse_linux_enterprise_live_patchingMatch12.0
OR
novellsuse_linux_enterprise_module_for_public_cloudMatch12
OR
novellsuse_linux_enterprise_serverMatch11.0extra
OR
novellsuse_linux_enterprise_serverMatch11.0sp4
OR
novellsuse_linux_enterprise_serverMatch12.0
OR
novellsuse_linux_enterprise_serverMatch12.0sp1
OR
novellsuse_linux_enterprise_workstation_extensionMatch12.0
OR
novellsuse_linux_enterprise_workstation_extensionMatch12.0sp1
Node
canonicalubuntu_linuxMatch12.04-
OR
canonicalubuntu_linuxMatch14.04esm
OR
canonicalubuntu_linuxMatch15.10
OR
canonicalubuntu_linuxMatch16.04esm
Node
debiandebian_linuxMatch8.0

References

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.8%