CVE-2016-0823
published 2016-03-12CVE-2016-0823: The pagemap_open function in fs/proc/task_mmu.c in the Linux kernel before 3.19.3, as used in Android 6.0.1 before 2016-03-01, allows local users to obtain…
PriorityP414medium4CVSS 3.0
AVLACLPRNUINSUCLINAN
EPSS
0.30%
22.8th percentile
The pagemap_open function in fs/proc/task_mmu.c in the Linux kernel before 3.19.3, as used in Android 6.0.1 before 2016-03-01, allows local users to obtain sensitive physical-address information by reading a pagemap file, aka Android internal bug 25739721.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.0.2-1 (bookworm) | linux 4.0.2-1 (bookworm) |
| android | — | — | |
| android | — | — | |
| linux | linux_kernel | <= 3.19.2 | — |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
CVSS provenance
nvdv3.04.0MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2016-0823: Android Security Bulletin 2016-03-01
CVE: CVE-2016-0823
Severity: HIGH
Affected AOSP versions: 6
vendor_android·2016-03-01·CVSS 4.0
CVE-2016-0823 [MEDIUM] CVE-2016-0823: Android Security Bulletin 2016-03-01
CVE: CVE-2016-0823
Severity: HIGH
Affected AOSP versions: 6
Android Security Bulletin 2016-03-01
CVE: CVE-2016-0823
Severity: HIGH
Affected AOSP versions: 6.0.1
Debian
CVE-2016-0823: linux - The pagemap_open function in fs/proc/task_mmu.c in the Linux kernel before 3.19....
vendor_debian·2016·CVSS 4.0
CVE-2016-0823 [MEDIUM] CVE-2016-0823: linux - The pagemap_open function in fs/proc/task_mmu.c in the Linux kernel before 3.19....
The pagemap_open function in fs/proc/task_mmu.c in the Linux kernel before 3.19.3, as used in Android 6.0.1 before 2016-03-01, allows local users to obtain sensitive physical-address information by reading a pagemap file, aka Android internal bug 25739721.
Scope: local
bookworm: resolved (fixed in 4.0.2-1)
bullseye: resolved (fixed in 4.0.2-1)
forky: resolved (fixed in 4.0.2-1)
sid: resolved (fixed in 4.0.2-1)
trixie: resolved (fixed in 4.0.2-1)
Red Hat
kernel: Leakage of physical address mappings to non-privileged userspace
vendor_redhat·2015-03-09·CVSS 4.0
CVE-2016-0823 [MEDIUM] CWE-732 kernel: Leakage of physical address mappings to non-privileged userspace
kernel: Leakage of physical address mappings to non-privileged userspace
The pagemap_open function in fs/proc/task_mmu.c in the Linux kernel before 3.19.3, as used in Android 6.0.1 before 2016-03-01, allows local users to obtain sensitive physical-address information by reading a pagemap file, aka Android internal bug 25739721.
Statement: This issue does not affect the Linux kernels as shipped with Red Hat Enterprise Linux 5.
This has been rated as having Low security impact and is not currently
planned to be addressed in future updates of 6, 7, and MRG-2. For additional
information, refer to the Red Hat Enterprise Linux Life Cycle:
https://access.redhat.com/support/policy/updates/errata/ .
Package: kernel (Red Hat Enterprise Linux 4) - Not affected
Package: kernel (Red Hat Enterprise
GHSA
GHSA-6mh6-g43h-xg4x: The pagemap_open function in fs/proc/task_mmu
ghsa_unreviewed·2022-05-17
CVE-2016-0823 [MEDIUM] CWE-200 GHSA-6mh6-g43h-xg4x: The pagemap_open function in fs/proc/task_mmu
The pagemap_open function in fs/proc/task_mmu.c in the Linux kernel before 3.19.3, as used in Android 6.0.1 before 2016-03-01, allows local users to obtain sensitive physical-address information by reading a pagemap file, aka Android internal bug 25739721.
OSV
CVE-2016-0823: The pagemap_open function in fs/proc/task_mmu
osv·2016-03-12·CVSS 4.0
CVE-2016-0823 [MEDIUM] CVE-2016-0823: The pagemap_open function in fs/proc/task_mmu
The pagemap_open function in fs/proc/task_mmu.c in the Linux kernel before 3.19.3, as used in Android 6.0.1 before 2016-03-01, allows local users to obtain sensitive physical-address information by reading a pagemap file, aka Android internal bug 25739721.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-0823 kernel: Leakage of physical address mappings to non-privileged userspace [fedora-all]
bugzilla·2016-04-14·CVSS 4.0
CVE-2016-0823 [MEDIUM] CVE-2016-0823 kernel: Leakage of physical address mappings to non-privileged userspace [fedora-all]
CVE-2016-0823 kernel: Leakage of physical address mappings to non-privileged userspace [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2016-0823 kernel: Leakage of physical address mappings to non-privileged userspace
bugzilla·2016-03-14·CVSS 4.0
CVE-2016-0823 [MEDIUM] CVE-2016-0823 kernel: Leakage of physical address mappings to non-privileged userspace
CVE-2016-0823 kernel: Leakage of physical address mappings to non-privileged userspace
It was reported that pagemap_open function in fs/proc/task_mmu.c in the Linux kernel before 3.19.3 allows local users to obtain sensitive physical-address information by reading a /proc//pagemap file.
The initial fix (commit ab676b7d6fbf4b294bf198fb27ade5b0e865c7ce) put the privilege check directly in the pagemap_open function, which was considered too coarse. Upstream later moved the check into pagemap_read with commit 1c90308e7a77af6742a97d1021cca923b23b7f0d. This allows /proc//pagemap to be opened and read by non-root users but it does not expose the physical addresses that could be used by the rowhammer exploit.
Upstream patch:
https://github.com/torvalds/linux/commit/ab676b7d6fbf4b294bf198fb27ad
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ab676b7d6fbf4b294bf198fb27ade5b0e865c7cehttp://googleprojectzero.blogspot.com/2015/03/exploiting-dram-rowhammer-bug-to-gain.htmlhttp://source.android.com/security/bulletin/2016-03-01.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.19.3http://www.securityfocus.com/bid/84265https://github.com/torvalds/linux/commit/ab676b7d6fbf4b294bf198fb27ade5b0e865c7cehttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ab676b7d6fbf4b294bf198fb27ade5b0e865c7cehttp://googleprojectzero.blogspot.com/2015/03/exploiting-dram-rowhammer-bug-to-gain.htmlhttp://source.android.com/security/bulletin/2016-03-01.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.19.3http://www.securityfocus.com/bid/84265https://github.com/torvalds/linux/commit/ab676b7d6fbf4b294bf198fb27ade5b0e865c7ce
2016-03-12
Published