CVE-2016-4558

Description

The BPF subsystem in the Linux kernel before 4.5.5 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted application on (1) a system with more than 32 Gb of memory, related to the program reference count or (2) a 1 Tb system, related to the map reference count.

Risk Information

Base Score
7.0
MODERATE
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.272

Associated Vulnerability

VulnerabilityOS Platform
Linux kernel (LSN-0026-1) linux-image-generic_4.4.0.87.93_i386.debLinux
Linux kernel (LSN-0026-1) linux-image-generic_4.4.0.87.93_amd64.debLinux
Linux kernel (LSN-0026-1) linux-image-lowlatency_4.4.0.87.93_i386.debLinux
Linux kernel (LSN-0026-1) linux-image-lowlatency_4.4.0.87.93_amd64.debLinux
Linux kernel (LSN-0026-1) linux-image-4.4.0-87-generic_4.4.0-87.110_i386.debLinux
Linux kernel (LSN-0026-1) linux-image-4.4.0-87-generic_4.4.0-87.110_amd64.debLinux
Linux kernel (LSN-0026-1) linux-image-4.4.0-87-lowlatency_4.4.0-87.110_i386.debLinux
Linux kernel (LSN-0026-1) linux-image-4.4.0-87-lowlatency_4.4.0-87.110_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234