CVE-2016-8733: Integer Overflow
An exploitable integer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFSADDENTRIES when dealing with native file systems. An attacker can craft an input that can cause a kernel panic and potentially be leveraged into a full privilege escalation vulnerability. This vulnerability is distinct from CVE-2016-9031.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8733?
CVE-2016-8733 is considered to be a critical vulnerability due to its potential to cause a kernel panic.
How do I fix CVE-2016-8733?
To fix CVE-2016-8733, update Joyent SmartOS to a version released after 20161110T013148Z that addresses this vulnerability.
What systems are affected by CVE-2016-8733?
CVE-2016-8733 affects Joyent SmartOS versions up to and including 20161110T013148Z.
What is the cause of the CVE-2016-8733 vulnerability?
The vulnerability in CVE-2016-8733 is caused by an exploitable integer overflow in the Hyprlofs file system's Ioctl system call.
Can CVE-2016-8733 be exploited remotely?
Yes, CVE-2016-8733 can potentially be exploited remotely by crafting specific inputs to trigger the kernel panic.