5.5

CVE-2016-0821

The LIST_POISON feature in include/linux/poison.h in the Linux kernel before 4.3, as used in Android 6.0.1 before 2016-03-01, does not properly consider the relationship to the mmap_min_addr value, which makes it easier for attackers to bypass a poison-pointer protection mechanism by triggering the use of an uninitialized list entry, aka Android internal bug 26186802, a different vulnerability than CVE-2015-3636.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 4.3
Google ≫ Android Version 6.0.1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.299
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:P/A:N
CWE-908 Use of Uninitialized Resource

The product uses or accesses a resource that has not been initialized.

http://www.ubuntu.com/usn/USN-2967-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2967-2
Third Party Advisory
http://source.android.com/security/bulletin/2016-03-01.html
Third Party Advisory
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8a5e5e02fc83aaf67053ab53b359af08c6c49aaf
Patch
Vendor Advisory
Issue Tracking
http://www.debian.org/security/2016/dsa-3607
Third Party Advisory
http://www.openwall.com/lists/oss-security/2015/05/02/6
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/84260
Third Party Advisory
VDB Entry
http://www.ubuntu.com/usn/USN-2968-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2968-2
Third Party Advisory
http://www.ubuntu.com/usn/USN-2969-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2970-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2971-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2971-2
Third Party Advisory
http://www.ubuntu.com/usn/USN-2971-3
Third Party Advisory
https://github.com/torvalds/linux/commit/8a5e5e02fc83aaf67053ab53b359af08c6c49aaf
Patch
Third Party Advisory
Issue Tracking