CVE-2016-1000006: Use After Free
Published Nov 19, 2019
·Updated
hhvm before 3.12.11 has a use-after-free in the serializememoizeparam() and ResourceBundle::construct() functions.
Affected Software
2 affected components
debian/hhvm
Facebook HHVM<3.12.11
Event History
Nov 19, 2019
CVE Published
via MITRE·02:51 PM
Data Sourced
via MITRE·02:51 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Feb 19, 2026
Data Sourced
via Ubuntu·03:46 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·03:48 PM
Description
Frequently Asked Questions
1
What is CVE-2016-1000006?
CVE-2016-1000006 is a vulnerability in hhvm before version 3.12.11 that allows for a use-after-free in the serialize_memoize_param() and ResourceBundle::__construct() functions.
2
How does CVE-2016-1000006 impact hhvm?
CVE-2016-1000006 can lead to a use-after-free vulnerability in hhvm before version 3.12.11, which could potentially allow an attacker to execute arbitrary code or cause a denial of service.
3
What is the severity of CVE-2016-1000006?
CVE-2016-1000006 has a severity rating of 9.8, which is considered critical.
4
How can I fix CVE-2016-1000006?
To fix CVE-2016-1000006, you should update hhvm to version 3.12.11 or later.
5
Where can I find more information about CVE-2016-1000006?
You can find more information about CVE-2016-1000006 at the following references: [1] [2] [3].