The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have unspecified other impact via a crafted isofs filesystem.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-516-1 | linux security update |
Debian DSA |
DSA-3607-1 | linux security update |
EUVD |
EUVD-2016-5888 | The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have unspecified other impact via a crafted isofs filesystem. |
Ubuntu USN |
USN-3016-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3016-2 | Linux kernel (Raspberry Pi 2) vulnerabilities |
Ubuntu USN |
USN-3016-3 | Linux kernel (Qualcomm Snapdragon) vulnerabilities |
Ubuntu USN |
USN-3016-4 | Linux kernel (Xenial HWE) vulnerabilities |
Ubuntu USN |
USN-3017-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3017-2 | Linux kernel (Raspberry Pi 2) vulnerabilities |
Ubuntu USN |
USN-3017-3 | Linux kernel (Wily HWE) vulnerabilities |
Ubuntu USN |
USN-3018-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3018-2 | Linux kernel (Trusty HWE) vulnerabilities |
Ubuntu USN |
USN-3019-1 | Linux kernel (Utopic HWE) vulnerabilities |
Ubuntu USN |
USN-3020-1 | Linux kernel (Vivid HWE) vulnerabilities |
Ubuntu USN |
USN-3021-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3021-2 | Linux kernel (OMAP4) vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: debian
Published:
Updated: 2024-08-06T00:46:39.243Z
Reserved: 2016-05-18T00:00:00
Link: CVE-2016-4913
No data.
Status : Deferred
Published: 2016-05-23T10:59:14.723
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-4913
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN