CVE-2016-5728 PUBLISHED

Race condition in the vop_ioctl function in drivers/misc/mic/vop/vop_vringh.c in the MIC VOP driver in the Linux kernel before 4.6.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (memory corruption and system crash) by changing a certain header, aka a "double fetch" vulnerability.

EPSS 0.05% · 14.8th percentile

Risk Scores

EPSS Score
0.05%
14.8th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlinux3.13.0-36.63, 3.11.0-12.19, 3.12.0-1.3
Ubuntu:16.04:LTSlinux-raspi24.2.0-1013.19, 4.4.0-1010.13, 4.4.0-1010.12
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1022.25, 4.4.0-1020.23, 4.4.0-1019.22
Ubuntu:14.04:LTSlinux-lts-xenial4.4.0-13.29~14.04.1, 4.4.0-34.53~14.04.1, 4.4.0-31.50~14.04.1
Ubuntu:16.04:LTSlinux4.4.0-10.25, 0, 4.2.0-16.19
Ubuntu:14.04:LTSlinux-lts-vivid3.19.0-30.34~14.04.1, 3.19.0-66.74~14.04.1, 3.19.0-65.73~14.04.1

Timeline

References

Open in Interactive Console →