Severity
7.8HIGHNVD
EPSS
0.2%
top 61.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 27
Latest updateMay 14

Description

The fork implementation in the Linux kernel before 4.5 on s390 platforms mishandles the case of four page-table levels, which allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a crafted application, related to arch/s390/include/asm/mmu_context.h and arch/s390/include/asm/pgalloc.h.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDlinux/linux_kernel2.6.253.2.79+4
Debianlinux/linux_kernel< 4.4.6-1+3

Also affects: Debian Linux 6.0, 7.0, 8.0, Enterprise Linux 7.0

Patches

🔴Vulnerability Details

5
GHSA
GHSA-h8j9-2jj6-73jj: The fork implementation in the Linux kernel before 42022-05-14
OSV
CVE-2016-2143: The fork implementation in the Linux kernel before 42016-04-27
CVEList
CVE-2016-2143: The fork implementation in the Linux kernel before 42016-04-27
Kernel
Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/s390/linux2016-03-10
Kernel
s390/mm: four page table levels vs. fork2016-02-15

📋Vendor Advisories

2
Red Hat
kernel: Fork of large process causes memory corruption2016-06-01
Debian
CVE-2016-2143: linux - The fork implementation in the Linux kernel before 4.5 on s390 platforms mishand...2016

💬Community

2
Bugzilla
CVE-2016-2143 kernel: Fork of large process causes memory corruption [fedora-all]2016-06-01
Bugzilla
CVE-2016-2143 kernel: Fork of large process causes memory corruption2016-02-16
CVE-2016-2143 — Improper Input Validation in Kernel | cvebase