First published: Tue Mar 07 2017(Updated: )
OpenBSD 5.8 and 5.9 allows certain local users with kern.usermount privileges to cause a denial of service (kernel panic) by mounting a tmpfs with a VNOVAL in the (1) username, (2) groupname, or (3) device name of the root node.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenBSD | =5.8 | |
OpenBSD | =5.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6246 has a medium severity classification due to its potential to cause a denial of service through kernel panic.
To fix CVE-2016-6246, upgrade your OpenBSD system to versions 5.8 or 5.9 that have been patched against this vulnerability.
CVE-2016-6246 affects local users on OpenBSD 5.8 and 5.9 who have kern.usermount privileges.
CVE-2016-6246 is related to a denial of service attack that can trigger a kernel panic.
Yes, CVE-2016-6246 is considered exploitable as it allows certain local users to cause a disruption in system service.