UBUNTU-CVE-2016-9644

Advisory lineage Upstream: 1 Downstream: 3
Published: 27 Nov 2016, 00:00
Last modified:22 Apr 2026, 11:06

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.8 HIGH
3.0 (osv_ubuntu)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

27 Nov 2016, 00:00
Published
Vulnerability first disclosed
22 Apr 2026, 11:06
Last Modified
Vulnerability information updated

Description

The __get_user_asm_ex macro in arch/x86/include/asm/uaccess.h in the Linux kernel 4.4.22 through 4.4.28 contains extended asm statements that are incompatible with the exception table, which allows local users to obtain root access on non-SMEP platforms via a crafted application. NOTE: this vulnerability exists because of incorrect backporting of the CVE-2016-9178 patch to older kernels.

CVSS Metrics

  • v3.0HIGHScore: 7.8CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Systems

  • ubuntulinux

    < 3.13.0-145.194 | < 4.4.0-51.72

  • ubuntulinux-lts-xenial

    < 4.4.0-51.72~14.04.1

  • ubuntulinux-snapdragon

    < 4.4.0-1042.46

References (8)