Vulnerability Description
An issue was discovered in fs/gfs2/rgrp.c in the Linux kernel before 4.8. A use-after-free is caused by the functions gfs2_clear_rgrpd and read_rindex_entry.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 4.8 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-SlackwarThird Party AdvisoryVDB Entry
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=36PatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00025.htmlMailing ListVendor Advisory
- https://seclists.org/bugtraq/2019/Nov/11Mailing ListThird Party Advisory
- https://support.f5.com/csp/article/K31332013Third Party AdvisoryVDB Entry
- https://support.f5.com/csp/article/K31332013?utm_source=f5support&%3Butm_medi
- https://usn.ubuntu.com/4145-1/VDB EntryVendor Advisory
- http://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-SlackwarThird Party AdvisoryVDB Entry
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=36PatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00025.htmlMailing ListVendor Advisory
- https://seclists.org/bugtraq/2019/Nov/11Mailing ListThird Party Advisory
- https://support.f5.com/csp/article/K31332013Third Party AdvisoryVDB Entry
- https://support.f5.com/csp/article/K31332013?utm_source=f5support&%3Butm_medi
FAQ
What is CVE-2016-10905?
CVE-2016-10905 is a vulnerability with a CVSS score of 7.8 (HIGH). An issue was discovered in fs/gfs2/rgrp.c in the Linux kernel before 4.8. A use-after-free is caused by the functions gfs2_clear_rgrpd and read_rindex_entry.
How severe is CVE-2016-10905?
CVE-2016-10905 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-10905?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.