HIGH · 7.8

CVE-2016-4913

The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensiti...

Vulnerability Description

The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have unspecified other impact via a crafted isofs filesystem.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CanonicalUbuntu Linux12.04
LinuxLinux Kernel< 3.2.81
OracleLinux6
NovellSuse Linux Enterprise Software Development Kit11.0
NovellSuse Linux Enterprise Debuginfo11.0
NovellSuse Linux Enterprise Server11.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-4913?

CVE-2016-4913 is a vulnerability with a CVSS score of 7.8 (HIGH). The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensiti...

How severe is CVE-2016-4913?

CVE-2016-4913 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-4913?

Check the references section above for vendor advisories and patch information. Affected products include: Canonical Ubuntu Linux, Linux Linux Kernel, Oracle Linux, Novell Suse Linux Enterprise Software Development Kit, Novell Suse Linux Enterprise Debuginfo.