CVE-2016-9756 PUBLISHED

arch/x86/kvm/emulate.c in the Linux kernel before 4.8.12 does not properly initialize Code Segment (CS) in certain error cases, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.

EPSS 0.03% · 8.6th percentile

Risk Scores

EPSS Score
0.03%
8.6th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlinux-lts-xenial4.4.0-57.78~14.04.1, 4.4.0-53.74~14.04.1, 4.4.0-51.72~14.04.1
Ubuntu:14.04:LTSlinux3.13.0-8.28, 3.13.0-10.30, 3.13.0-11.31
Ubuntu:16.04:LTSlinux4.4.0-16.32, 0, 4.2.0-16.19
Ubuntu:16.04:LTSlinux-aws0, 4.4.0-1001.10
Ubuntu:14.04:LTSlinux-lts-vivid3.19.0-51.57~14.04.1, 3.19.0-51.58~14.04.1, 3.19.0-56.62~14.04.1

Timeline

References

Open in Interactive Console →