CVE Database
/

CVE-2016-0774

Back to search

CVE-2016-0774

Published: Apr 27, 2016

Modified: Aug 5, 2024

PUBLISHED

Description

The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in a certain Linux kernel backport in the linux package before 3.2.73-2+deb7u3 on Debian wheezy and the kernel package before 3.10.0-229.26.2 on Red Hat Enterprise Linux (RHEL) 7.1 do not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted application, aka an "I/O vector array overrun." NOTE: this vulnerability exists because of an incorrect fix for CVE-2015-1805.

VendorProductVersions

n/a

n/a

affected
n/a

References

USN-2967-1
vendor-advisory
x_refsource_UBUNTU
SUSE-SU-2016:1038
vendor-advisory
x_refsource_SUSE
SUSE-SU-2016:1033
vendor-advisory
x_refsource_SUSE
DSA-3503
vendor-advisory
x_refsource_DEBIAN
SUSE-SU-2016:1034
vendor-advisory
x_refsource_SUSE
USN-2967-2
vendor-advisory
x_refsource_UBUNTU
RHSA-2016:0494
vendor-advisory
x_refsource_REDHAT
USN-2968-1
vendor-advisory
x_refsource_UBUNTU
SUSE-SU-2016:1035
vendor-advisory
x_refsource_SUSE
SUSE-SU-2016:1031
vendor-advisory
x_refsource_SUSE
SUSE-SU-2016:1037
vendor-advisory
x_refsource_SUSE
SUSE-SU-2016:1045
vendor-advisory
x_refsource_SUSE
USN-2968-2
vendor-advisory
x_refsource_UBUNTU
SUSE-SU-2016:1032
vendor-advisory
x_refsource_SUSE
SUSE-SU-2016:1039
vendor-advisory
x_refsource_SUSE
RHSA-2016:0617
vendor-advisory
x_refsource_REDHAT
SUSE-SU-2016:1041
vendor-advisory
x_refsource_SUSE
SUSE-SU-2016:1046
vendor-advisory
x_refsource_SUSE
84126
vdb-entry
x_refsource_BID
SUSE-SU-2016:1040
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now