CVE-2016-4913

high

Description

The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have unspecified other impact via a crafted isofs filesystem.

References

https://github.com/torvalds/linux/commit/99d825822eade8d827a1817357cbf3f889a552d6

https://bugzilla.redhat.com/show_bug.cgi?id=1337528

https://access.redhat.com/errata/RHSA-2018:3096

https://access.redhat.com/errata/RHSA-2018:3083

http://www.ubuntu.com/usn/USN-3021-2

http://www.ubuntu.com/usn/USN-3021-1

http://www.ubuntu.com/usn/USN-3020-1

http://www.ubuntu.com/usn/USN-3019-1

http://www.ubuntu.com/usn/USN-3018-2

http://www.ubuntu.com/usn/USN-3018-1

http://www.ubuntu.com/usn/USN-3017-3

http://www.ubuntu.com/usn/USN-3017-2

http://www.ubuntu.com/usn/USN-3017-1

http://www.ubuntu.com/usn/USN-3016-4

http://www.ubuntu.com/usn/USN-3016-3

http://www.ubuntu.com/usn/USN-3016-2

http://www.ubuntu.com/usn/USN-3016-1

http://www.securityfocus.com/bid/90730

http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html

http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html

http://www.openwall.com/lists/oss-security/2016/05/18/5

http://www.openwall.com/lists/oss-security/2016/05/18/3

http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.5

http://www.debian.org/security/2016/dsa-3607

http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.html

http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html

http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=99d825822eade8d827a1817357cbf3f889a552d6

Details

Source: Mitre, NVD

Published: 2016-05-23

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High