Resource exhaustion in Linux kernel - CVE-2016-1583
Published: October 1, 2016 / Updated: September 14, 2018
Vulnerability identifier: #VU4062
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-1583
CWE-ID: CWE-400
Exploitation vector: Local access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a local attacker to cause DoS condition and gain elevated privileges on the target system.
The weakness exists in the ecryptfs_privileged_open function in fs/ecryptfs/kthread.c due to stack memory consumption. A local attacker can cause the service to crash and gain elevated privileges via vectors involving crafted mmap calls for /proc pathnames, leading to recursive pagefault handling.
The weakness exists in the ecryptfs_privileged_open function in fs/ecryptfs/kthread.c due to stack memory consumption. A local attacker can cause the service to crash and gain elevated privileges via vectors involving crafted mmap calls for /proc pathnames, leading to recursive pagefault handling.
Affected software
Linux kernel
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Workstation
SUSE Linux
Ubuntu
Fedora
kernel (Red Hat package)
kernel
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Workstation
SUSE Linux
Ubuntu
Fedora
kernel (Red Hat package)
kernel
How to mitigate CVE-2016-1583
Update to version 4.6.3.
kernel (Red Hat package) - update to 2.6.32-642.11.1.el6
kernel - addressed in versions 4.4.14-200.fc22, 4.5.7-202.fc23, 4.6.3-300.fc24
kernel - addressed in versions 4.4.14-200.fc22, 4.5.7-202.fc23, 4.6.3-300.fc24