CVE-2016-4913
HIGH severity · CVSS 7.8 · Information disclosure
7.8CVSS HIGH
Summary
The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have unspecified other impact via a crafted isofs filesystem.
Impact & exploitability
Attack vectorLocal
Attack complexityLow
Privileges requiredLow
User interactionNone
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)1%
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Official patch: http://www.openwall.com/lists/oss-security/2016/05/18/3 ↗
Additional information
- NVD record
- http://www.openwall.com/lists/oss-security/2016/05/18/3Patch
- http://www.openwall.com/lists/oss-security/2016/05/18/5Patch
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=99d825822eade8d827a1817357cbf3f889a552d6Advisory
- http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.5Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.htmlAdvisory
- http://www.debian.org/security/2016/dsa-3607Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlAdvisory