imPC@ndo IT

Tracker / CVE-2015-5706

CVE-2015-5706

Medium 4.6

Use-after-free vulnerability in the path_openat function in fs/namei.c in the Linux kernel 3.x and 4.x before 4.0.4 allows local users to cause a denial of service or possibly have unspecified other impact via O_TMPFILE filesystem operations that leverage a duplicate cleanup operation.

Affected products and versions

canonical ubuntu_linux
debian debian_linux
linux linux_kernel · 3.0 → 3.19.8
linux linux_kernel · 4.0 → 4.0.4

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References