Lucene search

K
cve[email protected]CVE-2016-4805
HistoryMay 23, 2016 - 10:59 a.m.

CVE-2016-4805

2016-05-2310:59:13
CWE-416
web.nvd.nist.gov
106
cve-2016-4805
linux kernel
vulnerability
use-after-free
memory corruption
system crash
spinlock
nvd

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.1%

Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a network namespace, related to the ppp_register_net_channel and ppp_unregister_channel functions.

Affected configurations

NVD
Node
novellsuse_linux_enterprise_desktopMatch12.0-
Node
novellsuse_linux_enterprise_workstation_extensionMatch12.0-
Node
novellsuse_linux_enterprise_module_for_public_cloudMatch12.0-
Node
novellsuse_linux_enterprise_serverMatch11.0sp4
Node
novellsuse_linux_enterprise_module_for_public_cloudMatch12.0-
Node
novellopensuse_leapMatch42.1
Node
novellsuse_linux_enterprise_software_development_kitMatch11.0sp4
Node
redhatenterprise_linuxMatch6.0
Node
canonicalubuntu_linuxMatch12.04-lts
Node
linuxlinux_kernelRange2.6.30–3.2.80
OR
linuxlinux_kernelRange3.3–3.10.102
OR
linuxlinux_kernelRange3.11–3.12.59
OR
linuxlinux_kernelRange3.13–3.14.67
OR
linuxlinux_kernelRange3.15–3.16.35
OR
linuxlinux_kernelRange3.17–3.18.37
OR
linuxlinux_kernelRange3.19–4.1.28
OR
linuxlinux_kernelRange4.2–4.4.8
OR
linuxlinux_kernelRange4.5–4.5.2
Node
novellsuse_linux_enterprise_software_development_kitMatch12.0-
Node
novellsuse_linux_enterprise_workstation_extensionMatch12.0sp1
Node
novellsuse_linux_enterprise_serverMatch12.0-
Node
novellsuse_linux_enterprise_desktopMatch12.0sp1
Node
redhatenterprise_linuxMatch7.0
Node
oraclelinuxMatch6
Node
novellsuse_linux_enterprise_real_time_extensionMatch11.0sp4
Node
novellsuse_linux_enterprise_serverMatch12.0sp1
Node
novellsuse_linux_enterprise_real_time_extensionMatch12.0sp1
Node
novellsuse_linux_enterprise_software_development_kitMatch12.0sp1
Node
novellsuse_linux_enterprise_live_patchingMatch12.0-

References

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.1%