cbcvebase.
CVE-2016-4805
published 2016-05-23

CVE-2016-4805: Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a network namespace, related to the ppp_register_net_channel and ppp_unregister_channel functions.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debianlinux< linux 4.5.2-1 (bookworm)linux 4.5.2-1 (bookworm)
googleandroid
linuxlinux_kernel>= 0 < 4.5.2-14.5.2-1
linuxlinux_kernel>= 0 < 4.5.2-14.5.2-1
linuxlinux_kernel>= 0 < 4.5.2-14.5.2-1
linuxlinux_kernel>= 0 < 4.5.2-14.5.2-1
linuxlinux_kernel>= 2.6.30 < 3.2.803.2.80
linuxlinux_kernel>= 3.11 < 3.12.593.12.59
linuxlinux_kernel>= 3.13 < 3.14.673.14.67
linuxlinux_kernel>= 3.15 < 3.16.353.16.35
linuxlinux_kernel>= 3.17 < 3.18.373.18.37
linuxlinux_kernel>= 3.19 < 4.1.284.1.28
linuxlinux_kernel>= 3.3 < 3.10.1023.10.102
linuxlinux_kernel>= 4.2 < 4.4.84.4.8
linuxlinux_kernel>= 4.5 < 4.5.24.5.2
novellopensuse_leap
novellsuse_linux_enterprise_desktop
novellsuse_linux_enterprise_live_patching
novellsuse_linux_enterprise_module_for_public_cloud
novellsuse_linux_enterprise_real_time_extension
novellsuse_linux_enterprise_real_time_extension
novellsuse_linux_enterprise_server
novellsuse_linux_enterprise_server
novellsuse_linux_enterprise_software_development_kit

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH