cbcvebase.
CVE-2016-10906
published 2019-08-19

CVE-2016-10906: An issue was discovered in drivers/net/ethernet/arc/emac_main.c in the Linux kernel before 4.5. A use-after-free is caused by a race condition between the…

PriorityP429high7CVSS 3.0
AVLACHPRLUINSUCHIHAH
EPSS
0.37%
29.8th percentile
An issue was discovered in drivers/net/ethernet/arc/emac_main.c in the Linux kernel before 4.5. A use-after-free is caused by a race condition between the functions arc_emac_tx and arc_emac_tx_clean.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 4.5.1-1 (bookworm)linux 4.5.1-1 (bookworm)
linuxlinux_kernel< 4.54.5
linuxlinux_kernel>= 0 < 4.5.1-14.5.1-1
linuxlinux_kernel>= 0 < 4.5.1-14.5.1-1
linuxlinux_kernel>= 0 < 4.5.1-14.5.1-1
linuxlinux_kernel>= 0 < 4.5.1-14.5.1-1
linuxlinux_kernel>= 0 < 4.4.0-166.1954.4.0-166.195
pocoojinja2>= 0 < 2.8-1ubuntu0.12.8-1ubuntu0.1
pocoojinja2>= 0 < 2.10-1ubuntu0.18.04.12.10-1ubuntu0.18.04.1
pocoojinja2>= 0 < 2.7.2-2ubuntu0.1~esm12.7.2-2ubuntu0.1~esm1

CVSS provenance

nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv8.6HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.