CVE-2016-7042 PUBLISHED

The proc_keys_show function in security/keys/proc.c in the Linux kernel through 4.8.2, when the GNU Compiler Collection (gcc) stack protector is enabled, uses an incorrect buffer size for certain timeout data, which allows local users to cause a denial of service (stack memory corruption and panic) by reading the /proc/keys file.

EPSS 0.10% · 26.7th percentile

Risk Scores

EPSS Score
0.10%
26.7th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlinux4.4.0-42.62, 4.4.0-38.57, 4.4.0-36.55
Ubuntu:14.04:LTSlinux-lts-vivid0, 3.19.0-20.20~14.04.1, 3.19.0-21.21~14.04.1
Ubuntu:16.04:LTSlinux-raspi24.4.0-1023.29, 4.4.0-1029.36, 4.4.0-1034.41
Ubuntu:16.04:LTSlinux-snapdragon0, 4.4.0-1012.12, 4.4.0-1013.14
Ubuntu:14.04:LTSlinux3.13.0-71.114, 3.11.0-12.19, 3.12.0-1.3
Ubuntu:14.04:LTSlinux-lts-xenial4.4.0-45.66~14.04.1, 4.4.0-42.62~14.04.1, 4.4.0-38.57~14.04.1

Timeline

References

Open in Interactive Console →