CVE-2016-4913
Vulnerability Summary
Timeline
Description
The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have unspecified other impact via a crafted isofs filesystem.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- v3.0•HIGH•Score: 7.8CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- v2.0•HIGH•Score: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 0.51%• Percentile: 43%
Techniques & Countermeasures
- CWE-200•Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Affected Systems
- canonical•ubuntu_linux
12.04 | 14.04 | 15.10 | 16.04
- debian•linux
< 4.5.4-1 | < 4.5.4-1 | < 4.5.4-1 | < 4.5.4-1
- ubuntu•linux
< 3.13.0-91.138 | < 4.4.0-28.47
- ubuntu•linux-azure
all
- ubuntu•linux-azure-6.11
all
- ubuntu•linux-azure-fde
all
- ubuntu•linux-azure-fde-5.15
all
- ubuntu•linux-gcp
all
- ubuntu•linux-gcp-6.11
all
- ubuntu•linux-gke
all
- ubuntu•linux-gkeop
all
- ubuntu•linux-hwe
all
- ubuntu•linux-hwe-6.11
all
- ubuntu•linux-hwe-edge
all
- ubuntu•linux-intel-iot-realtime
all
- ubuntu•linux-lowlatency-hwe-6.11
all
- ubuntu•linux-lts-utopic
< 3.16.0-76.98~14.04.1
- ubuntu•linux-lts-vivid
< 3.19.0-64.72~14.04.1
- ubuntu•linux-lts-wily
< 4.2.0-41.48~14.04.1
- ubuntu•linux-lts-xenial
< 4.4.0-28.47~14.04.1
- ubuntu•linux-raspi-realtime
all
- ubuntu•linux-raspi2
< 4.4.0-1016.22 | all
- ubuntu•linux-realtime
all | all
- ubuntu•linux-riscv
all | all | all
- ubuntu•linux-snapdragon
< 4.4.0-1019.22
- linux•linux_kernel
< 3.2.81 | ≥ 3.3, < 3.10.102 | ≥ 3.11, < 3.12.60 | ≥ 3.13, < 3.14.70 | ≥ 3.15, < 3.16.36 | ≥ 3.17, < 3.18.34 | ≥ 3.19, < 4.1.25 | ≥ 4.2, < 4.4.11 | ≥ 4.5, < 4.5.5
- novell•suse_linux_enterprise_debuginfo
11.0:sp4
- novell•suse_linux_enterprise_server
11.0:extra | 11.0:sp4
- novell•suse_linux_enterprise_software_development_kit
11.0:sp4
- oracle•linux
6
References (44)
- https://access.redhat.com/errata/RHSA-2018:3083
- https://github.com/torvalds/linux/commit/99d825822eade8d827a1817357cbf3f889a552d6
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.ubuntu.com/usn/USN-3017-1
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.html
- http://www.ubuntu.com/usn/USN-3017-3
- http://www.ubuntu.com/usn/USN-3018-2
- http://www.ubuntu.com/usn/USN-3021-2
- https://bugzilla.redhat.com/show_bug.cgi?id=1337528
- http://www.ubuntu.com/usn/USN-3017-2
- http://www.ubuntu.com/usn/USN-3019-1
- http://www.debian.org/security/2016/dsa-3607
- http://www.ubuntu.com/usn/USN-3016-2
- http://www.ubuntu.com/usn/USN-3016-1
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html
- http://www.ubuntu.com/usn/USN-3021-1
- http://www.openwall.com/lists/oss-security/2016/05/18/5
- http://www.ubuntu.com/usn/USN-3018-1
- http://www.openwall.com/lists/oss-security/2016/05/18/3
- http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.5
- http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html
- http://www.securityfocus.com/bid/90730
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=99d825822eade8d827a1817357cbf3f889a552d6
- http://www.ubuntu.com/usn/USN-3016-3
- http://www.ubuntu.com/usn/USN-3016-4
- https://access.redhat.com/errata/RHSA-2018:3096
- http://www.ubuntu.com/usn/USN-3020-1
- https://ubuntu.com/security/CVE-2016-4913
- https://git.kernel.org/linus/99d825822eade8d827a1817357cbf3f889a552d6
- https://ubuntu.com/security/notices/USN-3016-1
- https://ubuntu.com/security/notices/USN-3016-2
- https://ubuntu.com/security/notices/USN-3017-1
- https://ubuntu.com/security/notices/USN-3017-3
- https://ubuntu.com/security/notices/USN-3016-3
- https://ubuntu.com/security/notices/USN-3016-4
- https://ubuntu.com/security/notices/USN-3017-2
- https://ubuntu.com/security/notices/USN-3020-1
- https://ubuntu.com/security/notices/USN-3018-2
- https://ubuntu.com/security/notices/USN-3018-1
- https://ubuntu.com/security/notices/USN-3019-1
- https://ubuntu.com/security/notices/USN-3021-2
- https://ubuntu.com/security/notices/USN-3021-1
- https://www.cve.org/CVERecord?id=CVE-2016-4913
- https://security-tracker.debian.org/tracker/CVE-2016-4913