Resource exhaustion in Linux kernel - CVE-2016-1583

 

Resource exhaustion in Linux kernel - CVE-2016-1583

Published: October 1, 2016 / Updated: September 14, 2018


Vulnerability identifier: #VU4062
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-1583
CWE-ID: CWE-400
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local attacker to cause DoS condition and gain elevated privileges on the target system.

The weakness exists in the ecryptfs_privileged_open function in fs/ecryptfs/kthread.c due to stack memory consumption. A local attacker can cause the service to crash and gain elevated privileges via vectors involving crafted mmap calls for /proc pathnames, leading to recursive pagefault handling.

Affected software

Linux kernel
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Workstation
SUSE Linux
Ubuntu
Fedora

kernel (Red Hat package)
kernel

How to mitigate CVE-2016-1583

Update to version 4.6.3.

kernel (Red Hat package) - update to 2.6.32-642.11.1.el6
kernel - addressed in versions 4.4.14-200.fc22, 4.5.7-202.fc23, 4.6.3-300.fc24

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins