First published: Thu Oct 27 2016(Updated: )
drivers/vfio/pci/vfio_pci_intrs.c in the Linux kernel through 4.8.11 misuses the kzalloc function, which allows local users to cause a denial of service (integer overflow) or have unspecified other impact by leveraging access to a vfio PCI device file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | <=4.8.11 | |
debian/linux | 5.10.223-1 5.10.234-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.17-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2016-9084.
The severity of CVE-2016-9084 is medium.
CVE-2016-9084 affects Linux kernel versions through 4.8.11.
CVE-2016-9084 can be exploited by local users with access to a vfio PCI device file.
The fix for CVE-2016-9084 is to upgrade to Linux kernel versions 3.13.0-132.181, 4.4.0-79.100, 4.9~, or a higher version.