VDB

ALPINE-CVE-2016-10012

ALPINE-CVE-2016-10012 PUBLISHED CVSS 7.800000190734863 HIGH

The shared memory manager (associated with pre-authentication compression) in sshd in OpenSSH before 7.4 does not ensure that a bounds check is enforced by all compilers, which might allows local users to gain privileges by leveraging access to a sandboxed privilege-separation process, related to the m_zback and m_zlib data structures.

Risk Scores

CVSS 3.0
7.800000190734863
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Alpine:v3.17openssh0, 0, 7.3
Alpine:v3.14openssh7.3, *, 5.1_p1-r1
Alpine:v3.18openssh7.3_p1-r0, 7.2_p2-r1, 7.2_p2-r0
Alpine:v3.3openssh6.2_p2-r2, 6.3_p1-r0, 6.3_p1-r1
Alpine:v3.12openssh5.9_p1-r2, 0, 7.3
Alpine:v3.24openssh0
Alpine:v3.10openssh6.9_p1-r4, 6.9_p1-r3, 6.9_p1-r2
Alpine:v3.23openssh6.9_p1-r5, *, 7.3_p1-r1
Alpine:v3.21openssh6.9_p1-r2, 7.2_p2-r0, 7.2_p2-r1
Alpine:v3.13openssh*, 0, 5.1_p1-r1
Alpine:v3.15openssh0, 7.2_p1-r0, *
Alpine:v3.16openssh5.1, 0, 5.1_p1-r1
Alpine:v3.19openssh*, *, *
Alpine:v3.11openssh6.2_p1-r3, 6.2_p2-r3, 6.4_p1-r3
Alpine:v3.22openssh6.1_p1-r2, 6.9, 6.8
Alpine:v3.5openssh5.8_p2-r1, 5.8_p2-r2, 5.9_p1-r0
Alpine:v3.4openssh5.9_p1-r2, 0, 5.1_p1-r1
Alpine:v3.7openssh7.2_p2-r0, 0, 5.1_p1-r2
Alpine:v3.9openssh0, 0, 7.3
Alpine:v3.20openssh7.2_p2-r0, 7.2_p1-r0, *

…and 2 more

Timeline

  • Jan 5, 2017 CVE Published
  • Apr 30, 2026 Distribution Patch
  • Jun 9, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›