CVE-2016-0758

Severity
7.8HIGH
EPSS
0.1%
top 64.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 27
Latest updateMay 17

Description

Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

Also affects: Ubuntu Linux 16.04, Enterprise Linux 7.2

🔴Vulnerability Details

5
GHSA
GHSA-jfqq-mmmm-xrc9: Integer overflow in lib/asn1_decoder2022-05-17
CVEList
CVE-2016-0758: Integer overflow in lib/asn1_decoder2016-06-27
OSV
CVE-2016-0758: Integer overflow in lib/asn1_decoder2016-06-27
OSV
linux vulnerabilities2016-05-16
Kernel
KEYS: Fix ASN.1 indefinite length object parsing2016-02-23

📋Vendor Advisories

12
Android
CVE-2016-0758: Android Security Bulletin 2016-10-01 CVE: CVE-2016-0758 Severity: CRITICAL References: A-29814470 Upstream kernel2016-10-01
Ubuntu
Linux kernel vulnerability2016-05-16
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerability2016-05-16
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities2016-05-16
Ubuntu
Linux kernel (Wily HWE) vulnerabilities2016-05-16

💬Community

2
Bugzilla
CVE-2016-0758 kernel: tags with indefinite length can corrupt pointers in asn1_find_indefinite_length() [fedora-all]2016-05-12
Bugzilla
CVE-2016-0758 kernel: tags with indefinite length can corrupt pointers in asn1_find_indefinite_length()2016-01-20
CVE-2016-0758 (HIGH CVSS 7.8) | Integer overflow in lib/asn1_decode | cvebase.io