CVE-2016-4805 PUBLISHED

Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a network namespace, related to the ppp_register_net_channel and ppp_unregister_channel functions.

EPSS 0.15% · 34.8th percentile

Risk Scores

EPSS Score
0.15%
34.8th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlinux-lts-xenial4.4.0-21.37~14.04.1, 4.4.0-18.34~14.04.1, 4.4.0-15.31~14.04.1
Ubuntu:14.04:LTSlinux-lts-vivid3.19.0-25.26~14.04.1, 3.19.0-26.28~14.04.1, 3.19.0-28.30~14.04.1
Ubuntu:16.04:LTSlinux4.4.0-16.32, 4.4.0-7.22, 4.4.0-8.23
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1012.12, 0
Ubuntu:16.04:LTSlinux-raspi24.2.0-1014.21, 4.3.0-1006.6, 4.4.0-1003.4
Ubuntu:14.04:LTSlinux3.13.0-53.89, 3.13.0-54.91, 3.13.0-55.92
Ubuntu:14.04:LTSlinux-lts-wily4.2.0-35.40~14.04.1, 4.2.0-34.39~14.04.1, 4.2.0-30.36~14.04.1

Timeline

References

Open in Interactive Console →