vendor:
Linux Kernel
by:
wally0813
5.5
CVSS
MEDIUM
Leak kernel pointer
200
CWE
Product Name: Linux Kernel
Affected Version From: Linux Kernel 4.4 (Ubuntu 16.04)
Affected Version To: Linux Kernel 4.4 (Ubuntu 16.04)
Patch Exists: YES
Related CWE: CVE-2016-4578
CPE: o:linux:linux_kernel:4.4
Metasploit:
https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2016-4578/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2016-4578/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp2-cve-2016-4578/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp3-cve-2016-4578/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2016-4578/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2016-4578/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2016-4578/
Other Scripts:
N/A
Platforms Tested: Ubuntu 16.04
2019
Linux Kernel 4.4 (Ubuntu 16.04) – Leak kernel pointer in snd_timer_user_ccallback()
If snd_timer_user_ccallback() doesn't initialize snd_timer_tread.event and snd_timer_tread.val, they are leaked by snd_timer_user_read()
Mitigation:
Update the Linux Kernel to the latest version