The ring_buffer_resize function in kernel/trace/ring_buffer.c in the profiling subsystem in the Linux kernel before 4.6.1 mishandles certain integer calculations, which allows local users to gain privileges by writing to the /sys/kernel/debug/tracing/buffer_size_kb file.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2024-08-06T02:59:03.555Z

Reserved: 2016-12-01T00:00:00

Link: CVE-2016-9754

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2017-01-05T11:59:00.193

Modified: 2024-11-21T03:01:42.693

Link: CVE-2016-9754

cve-icon Redhat

Severity : Important

Publid Date: 2016-05-13T00:00:00Z

Links: CVE-2016-9754 - Bugzilla