Vulnerability Description
Integer overflow in the uvm_map_isavail function in uvm/uvm_map.c in OpenBSD 5.9 allows local users to cause a denial of service (kernel panic) via a crafted mmap call, which triggers the new mapping to overlap with an existing mapping.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openbsd | Openbsd | 5.9 |
Related Weaknesses (CWE)
References
- http://ftp.openbsd.org/pub/OpenBSD/patches/5.9/common/023_uvmisavail.patch.sigPatch
- http://www.openwall.com/lists/oss-security/2016/08/02/12ExploitMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/08/02/8ExploitMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/92264
- http://ftp.openbsd.org/pub/OpenBSD/patches/5.9/common/023_uvmisavail.patch.sigPatch
- http://www.openwall.com/lists/oss-security/2016/08/02/12ExploitMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/08/02/8ExploitMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/92264
FAQ
What is CVE-2016-6522?
CVE-2016-6522 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Integer overflow in the uvm_map_isavail function in uvm/uvm_map.c in OpenBSD 5.9 allows local users to cause a denial of service (kernel panic) via a crafted mmap call, which triggers the new mapping ...
How severe is CVE-2016-6522?
CVE-2016-6522 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-6522?
Check the references section above for vendor advisories and patch information. Affected products include: Openbsd Openbsd.