CVE-2016-6156
published 2016-08-06CVE-2016-6156: Race condition in the ec_device_ioctl_xcmd function in drivers/platform/chrome/cros_ec_dev.c in the Linux kernel before 4.7 allows local users to cause a…
PriorityP416medium5.1CVSS 3.0
AVLACHPRNUINSUCNINAH
EPSS
0.27%
19.7th percentile
Race condition in the ec_device_ioctl_xcmd function in drivers/platform/chrome/cros_ec_dev.c in the Linux kernel before 4.7 allows local users to cause a denial of service (out-of-bounds array access) by changing a certain size value, aka a "double fetch" vulnerability.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.7.2-1 (bookworm) | linux 4.7.2-1 (bookworm) |
| linux | linux_kernel | <= 4.6.6 | — |
| linux | linux_kernel | >= 0 < 4.7.2-1 | 4.7.2-1 |
| linux | linux_kernel | >= 0 < 4.7.2-1 | 4.7.2-1 |
| linux | linux_kernel | >= 0 < 4.7.2-1 | 4.7.2-1 |
| linux | linux_kernel | >= 0 < 4.7.2-1 | 4.7.2-1 |
| linux | linux_kernel | >= 0 < 4.4.0-38.57 | 4.4.0-38.57 |
CVSS provenance
nvdv3.05.1MEDIUMCVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.1MEDIUM
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v2x3-97gq-36gp: Race condition in the ec_device_ioctl_xcmd function in drivers/platform/chrome/cros_ec_dev
ghsa_unreviewed·2022-05-17
CVE-2016-6156 [MEDIUM] CWE-362 GHSA-v2x3-97gq-36gp: Race condition in the ec_device_ioctl_xcmd function in drivers/platform/chrome/cros_ec_dev
Race condition in the ec_device_ioctl_xcmd function in drivers/platform/chrome/cros_ec_dev.c in the Linux kernel before 4.7 allows local users to cause a denial of service (out-of-bounds array access) by changing a certain size value, aka a "double fetch" vulnerability.
OSV
linux-raspi2 vulnerabilities
osv·2016-09-19·CVSS 6.5
CVE-2016-6136 [MEDIUM] linux-raspi2 vulnerabilities
linux-raspi2 vulnerabilities
Pengfei Wang discovered a race condition in the audit subsystem in the
Linux kernel. A local attacker could use this to corrupt audit logs or
disrupt system-call auditing. (CVE-2016-6136)
It was discovered that the powerpc and powerpc64 hypervisor-mode KVM
implementation in the Linux kernel for did not properly maintain state
about transactional memory. An unprivileged attacker in a guest could cause
a denial of service (CPU lockup) in the host OS. (CVE-2016-5412)
Pengfei Wang discovered a race condition in the Chrome OS embedded
controller device driver in the Linux kernel. A local attacker could use
this to cause a denial of service (system crash). (CVE-2016-6156)
OSV
linux vulnerabilities
osv·2016-09-19·CVSS 6.5
CVE-2016-6136 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Pengfei Wang discovered a race condition in the audit subsystem in the
Linux kernel. A local attacker could use this to corrupt audit logs or
disrupt system-call auditing. (CVE-2016-6136)
It was discovered that the powerpc and powerpc64 hypervisor-mode KVM
implementation in the Linux kernel for did not properly maintain state
about transactional memory. An unprivileged attacker in a guest could cause
a denial of service (CPU lockup) in the host OS. (CVE-2016-5412)
Pengfei Wang discovered a race condition in the Chrome OS embedded
controller device driver in the Linux kernel. A local attacker could use
this to cause a denial of service (system crash). (CVE-2016-6156)
OSV
linux-snapdragon vulnerabilities
osv·2016-09-19·CVSS 6.5
CVE-2016-6136 [MEDIUM] linux-snapdragon vulnerabilities
linux-snapdragon vulnerabilities
Pengfei Wang discovered a race condition in the audit subsystem in the
Linux kernel. A local attacker could use this to corrupt audit logs or
disrupt system-call auditing. (CVE-2016-6136)
It was discovered that the powerpc and powerpc64 hypervisor-mode KVM
implementation in the Linux kernel for did not properly maintain state
about transactional memory. An unprivileged attacker in a guest could cause
a denial of service (CPU lockup) in the host OS. (CVE-2016-5412)
Pengfei Wang discovered a race condition in the Chrome OS embedded
controller device driver in the Linux kernel. A local attacker could use
this to cause a denial of service (system crash). (CVE-2016-6156)
OSV
linux-lts-xenial vulnerabilities
osv·2016-09-19·CVSS 6.5
CVE-2016-6136 [MEDIUM] linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
USN-3084-1 fixed vulnerabilities in the Linux kernel for Ubuntu
16.04 LTS. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for
Ubuntu 14.04 LTS.
Pengfei Wang discovered a race condition in the audit subsystem in the
Linux kernel. A local attacker could use this to corrupt audit logs or
disrupt system-call auditing. (CVE-2016-6136)
It was discovered that the powerpc and powerpc64 hypervisor-mode KVM
implementation in the Linux kernel for did not properly maintain state
about transactional memory. An unprivileged attacker in a guest could cause
a denial of service (CPU lockup) in the host OS. (CVE-2016-5412)
Pengfei Wang discovered a race condition in the Chrome OS embedded
controller dev
OSV
CVE-2016-6156: Race condition in the ec_device_ioctl_xcmd function in drivers/platform/chrome/cros_ec_dev
osv·2016-08-06·CVSS 5.1
CVE-2016-6156 [MEDIUM] CVE-2016-6156: Race condition in the ec_device_ioctl_xcmd function in drivers/platform/chrome/cros_ec_dev
Race condition in the ec_device_ioctl_xcmd function in drivers/platform/chrome/cros_ec_dev.c in the Linux kernel before 4.7 allows local users to cause a denial of service (out-of-bounds array access) by changing a certain size value, aka a "double fetch" vulnerability.
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2016-09-19·CVSS 6.5
CVE-2016-5412 [MEDIUM] Linux kernel (Raspberry Pi 2) vulnerabilities
Title: Linux kernel (Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Pengfei Wang discovered a race condition in the audit subsystem in the
Linux kernel. A local attacker could use this to corrupt audit logs or
disrupt system-call auditing. (CVE-2016-6136)
It was discovered that the powerpc and powerpc64 hypervisor-mode KVM
implementation in the Linux kernel for did not properly maintain state
about transactional memory. An unprivileged attacker in a guest could cause
a denial of service (CPU lockup) in the host OS. (CVE-2016-5412)
Pengfei Wang discovered a race condition in the Chrome OS embedded
controller device driver in the Linux kernel. A local attacker could use
this to cause a denial of service (system crash). (CVE-2016-6156)
Instruct
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2016-09-19·CVSS 6.5
CVE-2016-5412 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
USN-3084-1 fixed vulnerabilities in the Linux kernel for Ubuntu
16.04 LTS. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for
Ubuntu 14.04 LTS.
Pengfei Wang discovered a race condition in the audit subsystem in the
Linux kernel. A local attacker could use this to corrupt audit logs or
disrupt system-call auditing. (CVE-2016-6136)
It was discovered that the powerpc and powerpc64 hypervisor-mode KVM
implementation in the Linux kernel for did not properly maintain state
about transactional memory. An unprivileged attacker in a guest could cause
a denial of service (CPU lockup) in the host OS. (CVE-2016-5412)
Pengf
Ubuntu
Linux kernel (Qualcomm Snapdragon) vulnerabilities
vendor_ubuntu·2016-09-19·CVSS 6.5
CVE-2016-5412 [MEDIUM] Linux kernel (Qualcomm Snapdragon) vulnerabilities
Title: Linux kernel (Qualcomm Snapdragon) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Pengfei Wang discovered a race condition in the audit subsystem in the
Linux kernel. A local attacker could use this to corrupt audit logs or
disrupt system-call auditing. (CVE-2016-6136)
It was discovered that the powerpc and powerpc64 hypervisor-mode KVM
implementation in the Linux kernel for did not properly maintain state
about transactional memory. An unprivileged attacker in a guest could cause
a denial of service (CPU lockup) in the host OS. (CVE-2016-5412)
Pengfei Wang discovered a race condition in the Chrome OS embedded
controller device driver in the Linux kernel. A local attacker could use
this to cause a denial of service (system crash). (CVE-2016-6156)
Ins
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-09-19·CVSS 6.5
CVE-2016-5412 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Pengfei Wang discovered a race condition in the audit subsystem in the
Linux kernel. A local attacker could use this to corrupt audit logs or
disrupt system-call auditing. (CVE-2016-6136)
It was discovered that the powerpc and powerpc64 hypervisor-mode KVM
implementation in the Linux kernel for did not properly maintain state
about transactional memory. An unprivileged attacker in a guest could cause
a denial of service (CPU lockup) in the host OS. (CVE-2016-5412)
Pengfei Wang discovered a race condition in the Chrome OS embedded
controller device driver in the Linux kernel. A local attacker could use
this to cause a denial of service (system crash). (CVE-2016-6156)
Instructions: After a sta
Red Hat
kernel: Race condition vulnerability in Chrome driver
vendor_redhat·2016-07-04·CVSS 5.1
CVE-2016-6156 [MEDIUM] CWE-362 kernel: Race condition vulnerability in Chrome driver
kernel: Race condition vulnerability in Chrome driver
Race condition in the ec_device_ioctl_xcmd function in drivers/platform/chrome/cros_ec_dev.c in the Linux kernel before 4.7 allows local users to cause a denial of service (out-of-bounds array access) by changing a certain size value, aka a "double fetch" vulnerability.
A timing flaw was found in the Chrome EC driver in the Linux kernel. An attacker could abuse timing to skip validation checks to copy additional data from userspace possibly increasing privilege or crashing the system.
Statement: This issue does not affect Red Hat Enterprise Linux products as they have not included this feature in any shipping products.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not aff
Debian
CVE-2016-6156: linux - Race condition in the ec_device_ioctl_xcmd function in drivers/platform/chrome/c...
vendor_debian·2016·CVSS 5.1
CVE-2016-6156 [MEDIUM] CVE-2016-6156: linux - Race condition in the ec_device_ioctl_xcmd function in drivers/platform/chrome/c...
Race condition in the ec_device_ioctl_xcmd function in drivers/platform/chrome/cros_ec_dev.c in the Linux kernel before 4.7 allows local users to cause a denial of service (out-of-bounds array access) by changing a certain size value, aka a "double fetch" vulnerability.
Scope: local
bookworm: resolved (fixed in 4.7.2-1)
bullseye: resolved (fixed in 4.7.2-1)
forky: resolved (fixed in 4.7.2-1)
sid: resolved (fixed in 4.7.2-1)
trixie: resolved (fixed in 4.7.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-6156 kernel: Race condition vulnerability in Chrome driver [fedora-all]
bugzilla·2016-07-07·CVSS 5.1
CVE-2016-6156 [MEDIUM] CVE-2016-6156 kernel: Race condition vulnerability in Chrome driver [fedora-all]
CVE-2016-6156 kernel: Race condition vulnerability in Chrome driver [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2016-6156 kernel: Race condition vulnerability in Chrome driver
bugzilla·2016-07-07·CVSS 5.1
CVE-2016-6156 [MEDIUM] CVE-2016-6156 kernel: Race condition vulnerability in Chrome driver
CVE-2016-6156 kernel: Race condition vulnerability in Chrome driver
Double-fetch vulnerability was found in /drivers/platform/chrome/cros_ec_dev.c in the Chrome driver in the Linux kernel before 4.6.1.
In function ec_device_ioctl_xcmd(), the driver fetches user space data by pointer arg via copy_from_user(), and this happens twice at line 137 and line 145 respectively.
Upstream bug:
https://bugzilla.kernel.org/show_bug.cgi?id=120131
Upstream patch:
https://github.com/torvalds/linux/commit/096cdc6f52225835ff503f987a0d68ef770bb78e
Bugtraq post:
http://seclists.org/bugtraq/2016/Jul/20
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1353491]
---
kernel-4.6.4-201.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, ple
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=096cdc6f52225835ff503f987a0d68ef770bb78ehttp://seclists.org/bugtraq/2016/Jul/20http://www.securityfocus.com/bid/91553https://bugzilla.kernel.org/show_bug.cgi?id=120131https://bugzilla.redhat.com/show_bug.cgi?id=1353490https://github.com/torvalds/linux/commit/096cdc6f52225835ff503f987a0d68ef770bb78ehttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=096cdc6f52225835ff503f987a0d68ef770bb78ehttp://seclists.org/bugtraq/2016/Jul/20http://www.securityfocus.com/bid/91553https://bugzilla.kernel.org/show_bug.cgi?id=120131https://bugzilla.redhat.com/show_bug.cgi?id=1353490https://github.com/torvalds/linux/commit/096cdc6f52225835ff503f987a0d68ef770bb78e
2016-08-06
Published