vendor:
Kernel
by:
Todor Donev
7,2
CVSS
HIGH
Integer Overflow
190
CWE
Product Name: Kernel
Affected Version From: 2.6.32-642
Affected Version To: 3.16.0-4
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2016
Linux Kernel 2.6.32-642 / 3.16.0-4 ‘inode’ Integer Overflow PoC
The inode is a data structure in a Unix-style file system which describes a filesystem object such as a file or a directory. Each inode stores the attributes and disk block locations of the object's data. Filesystem object attributes may include metadata, as well as owner and permission data. INODE can be overflowed by mapping a single file too many times, allowing for a local user to possibly gain root access.
Mitigation:
Ensure that the system is updated with the latest security patches and that the system is configured to use the latest security settings.