CVE-2004-1016: Low severity Linux Linux kernel vulnerability
The scmsend function in the scm layer for Linux kernel 2.4.x up to 2.4.28, and 2.6.x up to 2.6.9, allows local users to cause a denial of service (system hang) via crafted auxiliary messages that are passed to the sendmsg function, which causes a deadlock condition.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1016?
CVE-2004-1016 is classified as a high severity vulnerability due to its potential to cause a denial of service by inducing a system hang.
How do I fix CVE-2004-1016?
To mitigate CVE-2004-1016, it is recommended to update the Linux kernel to version 2.4.29 or 2.6.10 or later, which includes patches for this vulnerability.
Who is affected by CVE-2004-1016?
CVE-2004-1016 affects local users on Linux kernel versions 2.4.x up to 2.4.28 and 2.6.x up to 2.6.9.
What type of attack is CVE-2004-1016 associated with?
CVE-2004-1016 is associated with local denial-of-service attacks that exploit a deadlock condition in the scm layer.
Can CVE-2004-1016 be exploited remotely?
No, CVE-2004-1016 requires local access to the system, making it a local privilege escalation vulnerability.