[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247085

 
 

909

 
 

194218

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2016-9644Date: (C)2016-11-28   (M)2023-12-22


The __get_user_asm_ex macro in arch/x86/include/asm/uaccess.h in the Linux kernel 4.4.22 through 4.4.28 contains extended asm statements that are incompatible with the exception table, which allows local users to obtain root access on non-SMEP platforms via a crafted application. NOTE: this vulnerability exists because of incorrect backporting of the CVE-2016-9178 patch to older kernels.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 7.8CVSS Score : 9.3
Exploit Score: 1.8Exploit Score: 8.6
Impact Score: 5.9Impact Score: 10.0
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: MEDIUM
Privileges Required: NONEAuthentication: NONE
User Interaction: REQUIREDConfidentiality: COMPLETE
Scope: UNCHANGEDIntegrity: COMPLETE
Confidentiality: HIGHAvailability: COMPLETE
Integrity: HIGH 
Availability: HIGH 
  
Reference:
BID-94545
USN-3146-1
USN-3146-2
http://www.openwall.com/lists/oss-security/2016/11/07/4
https://lwn.net/Articles/705220/

CPE    7
cpe:/o:linux:linux_kernel:4.4.22
cpe:/o:linux:linux_kernel:4.4.23
cpe:/o:linux:linux_kernel:4.4.24
cpe:/o:linux:linux_kernel:4.4.25
...
CWE    1
CWE-264
OVAL    6
oval:org.secpod.oval:def:703374
oval:org.secpod.oval:def:703381
oval:org.secpod.oval:def:51682
oval:org.secpod.oval:def:52822
...

© SecPod Technologies