CVE-2016-6516
published 2016-08-06CVE-2016-6516: Race condition in the ioctl_file_dedupe_range function in fs/ioctl.c in the Linux kernel through 4.7 allows local users to cause a denial of service…
PriorityP434high7.4CVSS 3.0
AVLACHPRNUINSUCHIHAH
EPSS
0.95%
57.3th percentile
Race condition in the ioctl_file_dedupe_range function in fs/ioctl.c in the Linux kernel through 4.7 allows local users to cause a denial of service (heap-based buffer overflow) or possibly gain privileges by changing a certain count value, aka a "double fetch" vulnerability.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.7.2-1 (bookworm) | linux 4.7.2-1 (bookworm) |
| linux | linux_kernel | <= 4.7 | — |
| linux | linux_kernel | >= 0 < 4.7.2-1 | 4.7.2-1 |
| linux | linux_kernel | >= 0 < 4.7.2-1 | 4.7.2-1 |
| linux | linux_kernel | >= 0 < 4.7.2-1 | 4.7.2-1 |
| linux | linux_kernel | >= 0 < 4.7.2-1 | 4.7.2-1 |
CVSS provenance
nvdv3.07.4HIGHCVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv7.4HIGH
vendor_debian7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: vfs: ioctl: double fetch leading to heap overflow
vendor_redhat·2016-07-31·CVSS 7.4
CVE-2016-6516 [HIGH] kernel: vfs: ioctl: double fetch leading to heap overflow
kernel: vfs: ioctl: double fetch leading to heap overflow
Race condition in the ioctl_file_dedupe_range function in fs/ioctl.c in the Linux kernel through 4.7 allows local users to cause a denial of service (heap-based buffer overflow) or possibly gain privileges by changing a certain count value, aka a "double fetch" vulnerability.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2016-6516: linux - Race condition in the ioctl_file_dedupe_range function in fs/ioctl.c in the Linu...
vendor_debian·2016·CVSS 7.4
CVE-2016-6516 [HIGH] CVE-2016-6516: linux - Race condition in the ioctl_file_dedupe_range function in fs/ioctl.c in the Linu...
Race condition in the ioctl_file_dedupe_range function in fs/ioctl.c in the Linux kernel through 4.7 allows local users to cause a denial of service (heap-based buffer overflow) or possibly gain privileges by changing a certain count value, aka a "double fetch" vulnerability.
Scope: local
bookworm: resolved (fixed in 4.7.2-1)
bullseye: resolved (fixed in 4.7.2-1)
forky: resolved (fixed in 4.7.2-1)
sid: resolved (fixed in 4.7.2-1)
trixie: resolved (fixed in 4.7.2-1)
GHSA
GHSA-j5cv-c6j4-5gv8: Race condition in the ioctl_file_dedupe_range function in fs/ioctl
ghsa_unreviewed·2022-05-17
CVE-2016-6516 [HIGH] CWE-119 GHSA-j5cv-c6j4-5gv8: Race condition in the ioctl_file_dedupe_range function in fs/ioctl
Race condition in the ioctl_file_dedupe_range function in fs/ioctl.c in the Linux kernel through 4.7 allows local users to cause a denial of service (heap-based buffer overflow) or possibly gain privileges by changing a certain count value, aka a "double fetch" vulnerability.
OSV
CVE-2016-6516: Race condition in the ioctl_file_dedupe_range function in fs/ioctl
osv·2016-08-06·CVSS 7.4
CVE-2016-6516 [HIGH] CVE-2016-6516: Race condition in the ioctl_file_dedupe_range function in fs/ioctl
Race condition in the ioctl_file_dedupe_range function in fs/ioctl.c in the Linux kernel through 4.7 allows local users to cause a denial of service (heap-based buffer overflow) or possibly gain privileges by changing a certain count value, aka a "double fetch" vulnerability.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-6516 kernel: vfs: ioctl: double fetch leading to heap overflow [fedora-all]
bugzilla·2016-08-02·CVSS 7.4
CVE-2016-6516 [HIGH] CVE-2016-6516 kernel: vfs: ioctl: double fetch leading to heap overflow [fedora-all]
CVE-2016-6516 kernel: vfs: ioctl: double fetch leading to heap overflow [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versi
Bugzilla
CVE-2016-6516 kernel: vfs: ioctl: double fetch leading to heap overflow
bugzilla·2016-08-02·CVSS 7.4
CVE-2016-6516 [HIGH] CVE-2016-6516 kernel: vfs: ioctl: double fetch leading to heap overflow
CVE-2016-6516 kernel: vfs: ioctl: double fetch leading to heap overflow
It was found that a commit which moved certain functionality from btrfs to vfs ioctl introduced a double fetch issue:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/fs/ioctl.c?h=v4.5&id=54dbc15172375641ef03399e8f911d7165eb90fb
This flaw could lead to an undersized allocation and subsequent heap overflow with potentially controlled data. It has been patched in upstream here:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=10eec60ce79187686e052092e5383c99b4420a20
CVE request:
http://seclists.org/oss-sec/2016/q3/213
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1362458]
arXiv
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
arxiv_fulltext·2022-04-26
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
## Abstract
This paper presents a systematic study on the security of modern file systems,
following a vulnerability-centric perspective. Specifically,
we collected 377 file system vulnerabilities committed to the CVE database in the past 20 years.
We characterize them from four dimensions that include why the vulnerabilities appear,
how the vulnerabilities can be exploited, what consequences can arise,
and how the vulnerabilities are fixed. This way, we build a deep understanding of
the attack surfaces faced by file systems, the threats imposed by the attack surfaces,
and the good and bad practices in mitigating the attacks in file systems. We envision that our study
will bring insights toward
arXiv
Automated Detection, Exploitation, and Elimination of Double-Fetch Bugs using Modern CPU Features
arxiv_fulltext·2017-11-03
Automated Detection, Exploitation, and Elimination of Double-Fetch Bugs using Modern CPU Features
Automated Detection, Exploitation, and Elimination of Double-Fetch Bugs using Modern CPU Features
Michael Schwarz^1, Daniel Gruss^1, Moritz Lipp^1, Clémentine Maurice^2,\ Schuster^1, Anders Fogh^3, Stefan Mangard^1
^1 Graz University of Technology, Austria
^2 CNRS, IRISA, France
^3 G DATA Advanced Analytics, Germany
## Abstract
Double-fetch bugs are a special type of race condition, where an unprivileged execution thread is able to change a memory location between the time-of-check and time-of-use of a privileged execution thread.
If an unprivileged attacker changes the value at the right time, the privileged operation becomes inconsistent, leading to a change in control flow, and thus an escalation of privileges for the attacker.
More severely, such double-fetch bugs can be introduced
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=10eec60ce79187686e052092e5383c99b4420a20http://www.openwall.com/lists/oss-security/2016/07/31/6http://www.securityfocus.com/bid/92259https://bugzilla.redhat.com/show_bug.cgi?id=1362457https://github.com/torvalds/linux/commit/10eec60ce79187686e052092e5383c99b4420a20http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=10eec60ce79187686e052092e5383c99b4420a20http://www.openwall.com/lists/oss-security/2016/07/31/6http://www.securityfocus.com/bid/92259https://bugzilla.redhat.com/show_bug.cgi?id=1362457https://github.com/torvalds/linux/commit/10eec60ce79187686e052092e5383c99b4420a20
2016-08-06
Published