CVE-2016-9039: Medium severity Joyent SmartOS vulnerability
An exploitable denial of service exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFSADDENTRIES. An attacker can cause a buffer to be allocated and never freed. When repeatedly exploited this will result in memory exhaustion, resulting in a full system denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9039?
CVE-2016-9039 is classified as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2016-9039?
To fix CVE-2016-9039, it is recommended to upgrade to a patched version of the Joyent SmartOS that addresses this issue.
What type of attack can exploit CVE-2016-9039?
CVE-2016-9039 can be exploited by an attacker through the Ioctl system call using the command HYPRLOFS_ADD_ENTRIES to cause a denial of service.
What are the consequences of exploiting CVE-2016-9039?
Exploiting CVE-2016-9039 can lead to a denial of service by consuming system resources through unallocated buffers.
Which software is affected by CVE-2016-9039?
CVE-2016-9039 specifically affects Joyent SmartOS version 20161110T013148Z.