CVE-2016-5011: Medium severity util-linux vulnerability
The parsedosextended function in partitions/dos.c in the libblkid library in util-linux allows physically proximate attackers to cause a denial of service (memory consumption) via a crafted MSDOS partition table with an extended partition boot record at zero offset.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5011?
CVE-2016-5011 has been assigned a medium severity rating due to its potential for causing denial of service through memory consumption.
How do I fix CVE-2016-5011?
To fix CVE-2016-5011, update the libblkid library in util-linux to a version greater than 2.28 or apply any appropriate patches from your distribution vendor.
Who is affected by CVE-2016-5011?
CVE-2016-5011 affects systems running versions of util-linux up to 2.28, and certain versions of Red Hat Enterprise Linux and IBM PowerKVM.
What type of vulnerability is CVE-2016-5011?
CVE-2016-5011 is a denial of service vulnerability caused by improper handling of crafted MSDOS partition tables.
Can CVE-2016-5011 be exploited remotely?
CVE-2016-5011 requires local access to exploit, as it involves physically proximate attackers manipulating partition tables.