CVE-2016-10044: High severity Linux Linux Kernel vulnerability
Last updated 24 July 2024
Other sources
The aiomount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which makes it easier for local users to bypass intended SELinux W^X policy restrictions, and consequently gain privileges, via an iosetup system call.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
CVE-2016-10044
What is the description of this vulnerability?
The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which makes it easier for local users to bypass intended SELinux W^X policy restrictions, and consequently gain privileges, via an io_setup system call.
Which Linux kernel versions are affected by this vulnerability?
Linux kernel versions before 4.7.7 are affected.
How can local users exploit this vulnerability?
Local users can exploit this vulnerability by making an io_setup system call.
Are there any references for this vulnerability?
Yes, you can find references for this vulnerability at http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=22f6b4d34fcf039c63a94e7670e0da24f8575a5a, http://source.android.com/security/bulletin/2017-02-01.html, and http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.7.7