CVE-2016-9644 PUBLISHED

The __get_user_asm_ex macro in arch/x86/include/asm/uaccess.h in the Linux kernel 4.4.22 through 4.4.28 contains extended asm statements that are incompatible with the exception table, which allows local users to obtain root access on non-SMEP platforms via a crafted application. NOTE: this vulnerability exists because of incorrect backporting of the CVE-2016-9178 patch to older kernels.

EPSS 0.17% · 38.6th percentile

Risk Scores

EPSS Score
0.17%
38.6th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1039.43, 4.4.0-1035.39, 4.4.0-1032.36
Ubuntu:14.04:LTSlinux-lts-xenial4.4.0-42.62~14.04.1, 0, 4.4.0-47.68~14.04.1
Ubuntu:14.04:LTSlinux3.13.0-19.40, 3.13.0-20.42, 3.13.0-21.43
Ubuntu:16.04:LTSlinux4.4.0-9.24, 4.4.0-10.25, 4.4.0-11.26

Timeline

References

Open in Interactive Console →