CVE-2016-7914
published 2016-11-16CVE-2016-7914: The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.5.3 does not check whether a slot is a leaf, which allows…
PriorityP423medium5.5CVSS 3.0
AVLACLPRNUIRSUCHINAN
EPSS
2.04%
79.3th percentile
The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.5.3 does not check whether a slot is a leaf, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and out-of-bounds read) via an application that uses associative-array data structures, as demonstrated by the keyutils test suite.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.5.3-1 (bookworm) | linux 4.5.3-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | <= 4.5.2 | — |
| linux | linux_kernel | >= 0 < 4.5.3-1 | 4.5.3-1 |
| linux | linux_kernel | >= 0 < 4.5.3-1 | 4.5.3-1 |
| linux | linux_kernel | >= 0 < 4.5.3-1 | 4.5.3-1 |
| linux | linux_kernel | >= 0 < 4.5.3-1 | 4.5.3-1 |
| linux | linux_kernel | >= 0 < 3.13.0-129.178 | 3.13.0-129.178 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:C/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2017-08-29·CVSS 5.5
CVE-2016-7914 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3406-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.
It was discovered that an out of bounds read vulnerability existed in the
associative array implementation in the Linux kernel. A local attacker
could use this to cause a denial of service (system crash) or expose
sensitive information. (CVE-2016-7914)
It was discovered that a NULL pointer dereference existed in the Direct
Rendering Manager (DRM) driver for VMWare devices in the Linux kernel. A
local attacker could use this to cause a denial of service (system cras
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-08-28·CVSS 5.5
CVE-2016-7914 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that an out of bounds read vulnerability existed in the
associative array implementation in the Linux kernel. A local attacker
could use this to cause a denial of service (system crash) or expose
sensitive information. (CVE-2016-7914)
It was discovered that a NULL pointer dereference existed in the Direct
Rendering Manager (DRM) driver for VMWare devices in the Linux kernel. A
local attacker could use this to cause a denial of service (system crash).
(CVE-2017-7261)
It was discovered that the USB Cypress HID drivers for the Linux kernel did
not properly validate reported information from the device. An attacker
with physical access could use this to expose sensitive in
Android
CVE-2016-7914: Android Security Bulletin 2016-11-01
CVE: CVE-2016-7914
Severity: HIGH
References: A-30513364
Upstream
kernel
vendor_android·2016-11-01·CVSS 5.5
CVE-2016-7914 [MEDIUM] CVE-2016-7914: Android Security Bulletin 2016-11-01
CVE: CVE-2016-7914
Severity: HIGH
References: A-30513364
Upstream
kernel
Android Security Bulletin 2016-11-01
CVE: CVE-2016-7914
Severity: HIGH
References: A-30513364
Upstream
kernel
Red Hat
kernel: assoc_array: don't call compare_object() on a node
vendor_redhat·2016-04-06·CVSS 5.5
CVE-2016-7914 [MEDIUM] CWE-476 kernel: assoc_array: don't call compare_object() on a node
kernel: assoc_array: don't call compare_object() on a node
The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.5.3 does not check whether a slot is a leaf, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and out-of-bounds read) via an application that uses associative-array data structures, as demonstrated by the keyutils test suite.
The assoc_array_insert_into_terminal_node() function in 'lib/assoc_array.c' in the Linux kernel before 4.5.3 does not check whether a slot is a leaf, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and out-of-bounds read) via an application
Debian
CVE-2016-7914: linux - The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the L...
vendor_debian·2016·CVSS 5.5
CVE-2016-7914 [MEDIUM] CVE-2016-7914: linux - The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the L...
The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.5.3 does not check whether a slot is a leaf, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and out-of-bounds read) via an application that uses associative-array data structures, as demonstrated by the keyutils test suite.
Scope: local
bookworm: resolved (fixed in 4.5.3-1)
bullseye: resolved (fixed in 4.5.3-1)
forky: resolved (fixed in 4.5.3-1)
sid: resolved (fixed in 4.5.3-1)
trixie: resolved (fixed in 4.5.3-1)
GHSA
GHSA-92qx-54jr-58qw: The assoc_array_insert_into_terminal_node function in lib/assoc_array
ghsa_unreviewed·2022-05-14
CVE-2016-7914 [HIGH] CWE-125 GHSA-92qx-54jr-58qw: The assoc_array_insert_into_terminal_node function in lib/assoc_array
The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.5.3 does not check whether a slot is a leaf, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and out-of-bounds read) via an application that uses associative-array data structures, as demonstrated by the keyutils test suite.
OSV
linux vulnerabilities
osv·2017-08-28·CVSS 5.5
CVE-2016-7914 [MEDIUM] linux vulnerabilities
linux vulnerabilities
It was discovered that an out of bounds read vulnerability existed in the
associative array implementation in the Linux kernel. A local attacker
could use this to cause a denial of service (system crash) or expose
sensitive information. (CVE-2016-7914)
It was discovered that a NULL pointer dereference existed in the Direct
Rendering Manager (DRM) driver for VMWare devices in the Linux kernel. A
local attacker could use this to cause a denial of service (system crash).
(CVE-2017-7261)
It was discovered that the USB Cypress HID drivers for the Linux kernel did
not properly validate reported information from the device. An attacker
with physical access could use this to expose sensitive information (kernel
memory). (CVE-2017-7273)
A reference count bug was discovered
OSV
CVE-2016-7914: The assoc_array_insert_into_terminal_node function in lib/assoc_array
osv·2016-11-16·CVSS 5.5
CVE-2016-7914 [MEDIUM] CVE-2016-7914: The assoc_array_insert_into_terminal_node function in lib/assoc_array
The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.5.3 does not check whether a slot is a leaf, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and out-of-bounds read) via an application that uses associative-array data structures, as demonstrated by the keyutils test suite.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8d4a2ec1e0b41b0cf9a0c5cd4511da7f8e4f3de2http://rhn.redhat.com/errata/RHSA-2016-2574.htmlhttp://source.android.com/security/bulletin/2016-11-01.htmlhttp://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.3http://www.securityfocus.com/bid/94138https://github.com/torvalds/linux/commit/8d4a2ec1e0b41b0cf9a0c5cd4511da7f8e4f3de2http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8d4a2ec1e0b41b0cf9a0c5cd4511da7f8e4f3de2http://rhn.redhat.com/errata/RHSA-2016-2574.htmlhttp://source.android.com/security/bulletin/2016-11-01.htmlhttp://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.3http://www.securityfocus.com/bid/94138https://github.com/torvalds/linux/commit/8d4a2ec1e0b41b0cf9a0c5cd4511da7f8e4f3de2
2016-11-16
Published