CVE-2016-4794
published 2016-05-23CVE-2016-4794: Use-after-free vulnerability in mm/percpu.c in the Linux kernel through 4.6 allows local users to cause a denial of service (BUG) or possibly have unspecified…
PriorityP434high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.49%
39.7th percentile
Use-after-free vulnerability in mm/percpu.c in the Linux kernel through 4.6 allows local users to cause a denial of service (BUG) or possibly have unspecified other impact via crafted use of the mmap and bpf system calls.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 4.6.2-2 (bookworm) | linux 4.6.2-2 (bookworm) |
| android | — | — | |
| linux | linux_kernel | >= 0 < 4.6.2-2 | 4.6.2-2 |
| linux | linux_kernel | >= 0 < 4.6.2-2 | 4.6.2-2 |
| linux | linux_kernel | >= 0 < 4.6.2-2 | 4.6.2-2 |
| linux | linux_kernel | >= 0 < 4.6.2-2 | 4.6.2-2 |
| linux | linux_kernel | >= 0 < 4.4.0-34.53 | 4.4.0-34.53 |
| linux | linux_kernel | >= 3.18 < 3.18.37 | 3.18.37 |
| linux | linux_kernel | >= 3.19 < 4.1.28 | 4.1.28 |
| linux | linux_kernel | >= 4.2 < 4.4.16 | 4.4.16 |
| linux | linux_kernel | >= 4.5 < 4.6.5 | 4.6.5 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2016-4794: Android Security Bulletin 2016-12-01
CVE: CVE-2016-4794
Severity: CRITICAL
References: A-31596597
Upstream kernel
[2]
vendor_android·2016-12-01·CVSS 7.8
CVE-2016-4794 [HIGH] CVE-2016-4794: Android Security Bulletin 2016-12-01
CVE: CVE-2016-4794
Severity: CRITICAL
References: A-31596597
Upstream kernel
[2]
Android Security Bulletin 2016-12-01
CVE: CVE-2016-4794
Severity: CRITICAL
References: A-31596597
Upstream kernel
[2]
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2016-08-10·CVSS 7.8
CVE-2016-3135 [HIGH] Linux kernel (Raspberry Pi 2) vulnerabilities
Title: Linux kernel (Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hawkes discovered an integer overflow in the Linux netfilter
implementation. On systems running 32 bit kernels, a local unprivileged
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code with administrative privileges.
(CVE-2016-3135)
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Sasha Levin discovered that a use-after-free existed in the percpu
allocator in the Linux kernel. A local attacker could use thi
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-08-10·CVSS 7.8
CVE-2016-3135 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hawkes discovered an integer overflow in the Linux netfilter
implementation. On systems running 32 bit kernels, a local unprivileged
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code with administrative privileges.
(CVE-2016-3135)
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Sasha Levin discovered that a use-after-free existed in the percpu
allocator in the Linux kernel. A local attacker could use this to cause a
deni
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities
vendor_ubuntu·2016-08-10·CVSS 5.5
CVE-2016-1237 [MEDIUM] Linux kernel (Vivid HWE) vulnerabilities
Title: Linux kernel (Vivid HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Sasha Levin discovered that a use-after-free existed in the percpu
allocator in the Linux kernel. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code with
administrative privileges. (CVE-2016-4
Ubuntu
Linux kernel (Qualcomm Snapdragon) vulnerabilities
vendor_ubuntu·2016-08-10·CVSS 7.8
CVE-2016-3135 [HIGH] Linux kernel (Qualcomm Snapdragon) vulnerabilities
Title: Linux kernel (Qualcomm Snapdragon) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hawkes discovered an integer overflow in the Linux netfilter
implementation. On systems running 32 bit kernels, a local unprivileged
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code with administrative privileges.
(CVE-2016-3135)
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Sasha Levin discovered that a use-after-free existed in the percpu
allocator in the Linux kernel. A local attacker could us
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2016-08-10·CVSS 7.8
CVE-2016-3135 [HIGH] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hawkes discovered an integer overflow in the Linux netfilter
implementation. On systems running 32 bit kernels, a local unprivileged
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code with administrative privileges.
(CVE-2016-3135)
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Sasha Levin discovered that a use-after-free existed in the percpu
allocator in the Linux kernel. A local attacker could use this to
Red Hat
kernel: Use after free in array_map_alloc
vendor_redhat·2016-04-17·CVSS 7.8
CVE-2016-4794 [HIGH] CWE-416 kernel: Use after free in array_map_alloc
kernel: Use after free in array_map_alloc
Use-after-free vulnerability in mm/percpu.c in the Linux kernel through 4.6 allows local users to cause a denial of service (BUG) or possibly have unspecified other impact via crafted use of the mmap and bpf system calls.
Use after free vulnerability was found in percpu using previously allocated memory in bpf. First __alloc_percpu_gfp() is called, then the memory is freed with free_percpu() which triggers async pcpu_balance_work and then pcpu_extend_area_map could use a chunk after it has been freed.
Statement: This issue does not affect the Linux kernels as shipped with Red Hat Enterprise Linux 4, 5 and 6.
This issue affects the Linux kernels as shipped with Red Hat Enterprise Linux 7 and MRG-2 and may be addressed in a future update.
Package
Debian
CVE-2016-4794: linux - Use-after-free vulnerability in mm/percpu.c in the Linux kernel through 4.6 allo...
vendor_debian·2016·CVSS 7.8
CVE-2016-4794 [HIGH] CVE-2016-4794: linux - Use-after-free vulnerability in mm/percpu.c in the Linux kernel through 4.6 allo...
Use-after-free vulnerability in mm/percpu.c in the Linux kernel through 4.6 allows local users to cause a denial of service (BUG) or possibly have unspecified other impact via crafted use of the mmap and bpf system calls.
Scope: local
bookworm: resolved (fixed in 4.6.2-2)
bullseye: resolved (fixed in 4.6.2-2)
forky: resolved (fixed in 4.6.2-2)
sid: resolved (fixed in 4.6.2-2)
trixie: resolved (fixed in 4.6.2-2)
GHSA
GHSA-6xwx-g6w8-mw46: Use-after-free vulnerability in mm/percpu
ghsa_unreviewed·2022-05-14
CVE-2016-4794 [HIGH] GHSA-6xwx-g6w8-mw46: Use-after-free vulnerability in mm/percpu
Use-after-free vulnerability in mm/percpu.c in the Linux kernel through 4.6 allows local users to cause a denial of service (BUG) or possibly have unspecified other impact via crafted use of the mmap and bpf system calls.
OSV
linux vulnerabilities
osv·2016-08-10·CVSS 7.8
CVE-2016-3135 [HIGH] linux vulnerabilities
linux vulnerabilities
Ben Hawkes discovered an integer overflow in the Linux netfilter
implementation. On systems running 32 bit kernels, a local unprivileged
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code with administrative privileges.
(CVE-2016-3135)
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Sasha Levin discovered that a use-after-free existed in the percpu
allocator in the Linux kernel. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code with
admin
OSV
linux-lts-xenial vulnerabilities
osv·2016-08-10·CVSS 7.8
CVE-2016-3135 [HIGH] linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
Ben Hawkes discovered an integer overflow in the Linux netfilter
implementation. On systems running 32 bit kernels, a local unprivileged
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code with administrative privileges.
(CVE-2016-3135)
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Sasha Levin discovered that a use-after-free existed in the percpu
allocator in the Linux kernel. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code
OSV
linux-snapdragon vulnerabilities
osv·2016-08-10·CVSS 7.8
CVE-2016-3135 [HIGH] linux-snapdragon vulnerabilities
linux-snapdragon vulnerabilities
Ben Hawkes discovered an integer overflow in the Linux netfilter
implementation. On systems running 32 bit kernels, a local unprivileged
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code with administrative privileges.
(CVE-2016-3135)
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Sasha Levin discovered that a use-after-free existed in the percpu
allocator in the Linux kernel. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code
OSV
linux-raspi2 vulnerabilities
osv·2016-08-10·CVSS 7.8
CVE-2016-3135 [HIGH] linux-raspi2 vulnerabilities
linux-raspi2 vulnerabilities
Ben Hawkes discovered an integer overflow in the Linux netfilter
implementation. On systems running 32 bit kernels, a local unprivileged
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code with administrative privileges.
(CVE-2016-3135)
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Sasha Levin discovered that a use-after-free existed in the percpu
allocator in the Linux kernel. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code wit
OSV
linux-lts-vivid vulnerabilities
osv·2016-08-10·CVSS 5.5
CVE-2016-1237 [MEDIUM] linux-lts-vivid vulnerabilities
linux-lts-vivid vulnerabilities
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Sasha Levin discovered that a use-after-free existed in the percpu
allocator in the Linux kernel. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code with
administrative privileges. (CVE-2016-4794)
Kangjie Lu discovered an information leak in the netlink implementatio
OSV
CVE-2016-4794: Use-after-free vulnerability in mm/percpu
osv·2016-05-23·CVSS 7.8
CVE-2016-4794 [HIGH] CVE-2016-4794: Use-after-free vulnerability in mm/percpu
Use-after-free vulnerability in mm/percpu.c in the Linux kernel through 4.6 allows local users to cause a denial of service (BUG) or possibly have unspecified other impact via crafted use of the mmap and bpf system calls.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-4794 kernel: Use after free in array_map_alloc [fedora-all]
bugzilla·2016-05-13·CVSS 7.8
CVE-2016-4794 [HIGH] CVE-2016-4794 kernel: Use after free in array_map_alloc [fedora-all]
CVE-2016-4794 kernel: Use after free in array_map_alloc [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. W
Bugzilla
CVE-2016-4794 kernel: Use after free in array_map_alloc
bugzilla·2016-05-13·CVSS 7.8
CVE-2016-4794 [HIGH] CVE-2016-4794 kernel: Use after free in array_map_alloc
CVE-2016-4794 kernel: Use after free in array_map_alloc
Use after free vulnerability was found in percpu using previously allocated memory in bpf. First __alloc_percpu_gfp() is called, then the memory is freed with free_percpu() which triggers async pcpu_balance_work and then pcpu_extend_area_map is hitting use-after-free.
CVE request (contains reproducer):
http://seclists.org/oss-sec/2016/q2/332
1: percpu: fix synchronization between chunk->map_extend_work and chunk destruction
( https://www.mail-archive.com/[email protected]/msg111820.html )
2: percpu: fix synchronization between synchronous map extension and chunk destruction
( https://www.mail-archive.com/[email protected]/msg111747.html )
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bu
http://rhn.redhat.com/errata/RHSA-2016-2574.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2584.htmlhttp://www.openwall.com/lists/oss-security/2016/05/12/6http://www.securityfocus.com/bid/90625http://www.ubuntu.com/usn/USN-3053-1http://www.ubuntu.com/usn/USN-3054-1http://www.ubuntu.com/usn/USN-3055-1http://www.ubuntu.com/usn/USN-3056-1http://www.ubuntu.com/usn/USN-3057-1https://bugzilla.redhat.com/show_bug.cgi?id=1335889https://lkml.org/lkml/2016/4/17/125https://source.android.com/security/bulletin/2016-12-01.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2574.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2584.htmlhttp://www.openwall.com/lists/oss-security/2016/05/12/6http://www.securityfocus.com/bid/90625http://www.ubuntu.com/usn/USN-3053-1http://www.ubuntu.com/usn/USN-3054-1http://www.ubuntu.com/usn/USN-3055-1http://www.ubuntu.com/usn/USN-3056-1http://www.ubuntu.com/usn/USN-3057-1https://bugzilla.redhat.com/show_bug.cgi?id=1335889https://lkml.org/lkml/2016/4/17/125https://source.android.com/security/bulletin/2016-12-01.html
2016-05-23
Published