The ring_buffer_resize function in kernel/trace/ring_buffer.c in the profiling subsystem in the Linux kernel before 4.6.1 mishandles certain integer calculations, which allows local users to gain privileges by writing to the /sys/kernel/debug/tracing/buffer_size_kb file.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published: 2017-01-05T11:00:00

Updated: 2024-08-06T02:59:03.555Z

Reserved: 2016-12-01T00:00:00

Link: CVE-2016-9754

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-01-05T11:59:00.193

Modified: 2023-01-17T21:05:25.067

Link: CVE-2016-9754

cve-icon Redhat

Severity : Important

Publid Date: 2016-05-13T00:00:00Z

Links: CVE-2016-9754 - Bugzilla