CVE-2016-10905

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

An issue was discovered in fs/gfs2/rgrp.c in the Linux kernel before 4.8. A use-after-free is caused by the functions gfs2_clear_rgrpd and read_rindex_entry.

References

http://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.html

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=36e4ad0316c017d5b271378ed9a1c9a4b77fab5f

https://lists.debian.org/debian-lts-announce/2019/09/msg00025.html

https://support.f5.com/csp/article/K31332013

https://support.f5.com/csp/article/K31332013?utm_source=f5support&utm_medium=RSS

https://usn.ubuntu.com/4145-1/

Details

Source: MITRE

Published: 2019-08-19

Updated: 2019-09-25

Type: CWE-416

Risk Information

CVSS v2

Base Score: 6.1

Vector: AV:L/AC:L/Au:N/C:P/I:P/A:C

Impact Score: 8.5

Exploitability Score: 3.9

Severity: MEDIUM

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Tenable Plugins

View all (9 total)

IDNameProductFamilySeverity
141374OracleVM 3.4 : Unbreakable / etc (OVMSA-2020-0044)NessusOracleVM Local Security Checks
critical
141367Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2020-5879)NessusOracle Linux Local Security Checks
high
141207Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2020-5866)NessusOracle Linux Local Security Checks
critical
132499NewStart CGSL CORE 5.04 / MAIN 5.04 : kernel-rt Multiple Vulnerabilities (NS-SA-2019-0266)NessusNewStart CGSL Local Security Checks
high
132490NewStart CGSL CORE 5.04 / MAIN 5.04 : kernel Multiple Vulnerabilities (NS-SA-2019-0264)NessusNewStart CGSL Local Security Checks
high
130751Slackware 14.2 : Slackware 14.2 kernel (SSA:2019-311-01)NessusSlackware Local Security Checks
critical
129491Ubuntu 16.04 LTS : linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities (USN-4145-1)NessusUbuntu Local Security Checks
critical
129361Debian DLA-1930-1 : linux security updateNessusDebian Local Security Checks
critical
129293Photon OS 1.0: Linux PHSA-2019-1.0-0251NessusPhotonOS Local Security Checks
high