First published: Wed Jan 18 2017(Updated: )
Last updated 24 July 2024
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | >=4.8.0<4.8.13 | |
debian/linux | 5.10.223-1 5.10.226-1 6.1.115-1 6.1.119-1 6.11.10-1 6.12.5-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10150 is a use-after-free vulnerability in the kvm_ioctl_create_device function in the Linux kernel before version 4.8.13.
CVE-2016-10150 allows host OS users to cause a denial of service (host OS crash) or possibly gain privileges via crafted ioctl calls on the /dev/kvm device.
CVE-2016-10150 has a severity rating of high.
To fix CVE-2016-10150, you should update to Linux kernel version 4.8.13 or later.
More information about CVE-2016-10150 can be found at the following references: [1](http://www.securityfocus.com/bid/95672), [2](http://www.openwall.com/lists/oss-security/2017/01/18/10), [3](http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a0f1d21c1ccb1da66629627a74059dd7f5ac9c61).