7.8
CVE-2016-5828
- EPSS 0.45%
- Veröffentlicht 27.06.2016 10:59:13
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, which allows local users to cause a denial of service (invalid process state or TM Bad Thing exception, and system crash) or possibly have unspecified other impact by starting and suspending a transaction before an exec system call.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 3.9 < 3.10.103
Linux ≫ Linux Kernel Version >= 3.11 < 3.14.74
Linux ≫ Linux Kernel Version >= 3.15 < 3.16.37
Linux ≫ Linux Kernel Version >= 3.17 < 3.18.37
Linux ≫ Linux Kernel Version >= 3.19 < 4.1.28
Linux ≫ Linux Kernel Version >= 4.2 < 4.4.16
Linux ≫ Linux Kernel Version >= 4.6 < 4.6.5
Novell ≫ Suse Linux Enterprise Real Time Extension Version 12 Update sp1
Debian ≫ Debian Linux Version 8.0
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.45% | 0.358 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.html
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.html
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.html
http://rhn.redhat.com/errata/RHSA-2016-2574.html
http://www.debian.org/security/2016/dsa-3616
http://www.ubuntu.com/usn/USN-3070-1
http://www.ubuntu.com/usn/USN-3070-2
http://www.ubuntu.com/usn/USN-3070-3
http://www.ubuntu.com/usn/USN-3070-4
http://www.ubuntu.com/usn/USN-3071-1
http://www.ubuntu.com/usn/USN-3071-2
http://www.openwall.com/lists/oss-security/2016/06/25/7
http://www.securityfocus.com/bid/91415
https://patchwork.ozlabs.org/patch/636776/