ZeroHour

CVE-2016-4913

CVSS 3.1
7.8 high
EPSS
<1%p42
Published
()
Modified
Description

The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have unspecified other impact via a crafted isofs filesystem.

Vendors
canonicallinuxoraclenovell
Products
ubuntu linux, linux kernel, linux, suse linux enterprise software development kit, suse linux enterprise debuginfo, suse linux enterprise server
Weakness
CWE-200
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.