cbcvebase.
CVE-2016-6130
published 2016-07-03

CVE-2016-6130: Race condition in the sclp_ctl_ioctl_sccb function in drivers/s390/char/sclp_ctl.c in the Linux kernel before 4.6 allows local users to obtain sensitive…

PriorityP418medium4.7CVSS 3.0
AVLACHPRLUINSUCHINAN
EPSS
0.26%
18.1th percentile
Race condition in the sclp_ctl_ioctl_sccb function in drivers/s390/char/sclp_ctl.c in the Linux kernel before 4.6 allows local users to obtain sensitive information from kernel memory by changing a certain length value, aka a "double fetch" vulnerability.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 4.6.1-1 (bookworm)linux 4.6.1-1 (bookworm)
linuxlinux_kernel<= 4.5.5
linuxlinux_kernel>= 0 < 4.6.1-14.6.1-1
linuxlinux_kernel>= 0 < 4.6.1-14.6.1-1
linuxlinux_kernel>= 0 < 4.6.1-14.6.1-1
linuxlinux_kernel>= 0 < 4.6.1-14.6.1-1
linuxlinux_kernel>= 0 < 4.4.0-42.624.4.0-42.62

CVSS provenance

nvdv3.04.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
vendor_ubuntu4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.