CVE-2016-9576: Use After Free

Published Nov 25, 2016
·
Updated

It was found that the blkrqmapuseriov() function in the Linux kernel's block device implementation did not properly restrict the type of iterator, which could allow a local attacker to read or write to arbitrary kernel memory locations or cause a denial of service (use-after-free) by leveraging write access to a /dev/sg device.

Other sources

The blkrqmapuseriov function in block/blk-map.c in the Linux kernel before 4.8.14 does not properly restrict the type of iterator, which allows local users to read or write to arbitrary kernel memory locations or cause a denial of service (use-after-free) by leveraging access to a /dev/sg device.

Use-after-free vulnerability in SCSI generic device interface has been reported which allows kernel memory read/write when having access to /dev/sg SCSI generic devices. This issue affects versions of Linux down to 2.6. This was assigned CVE-2016-9576.

Initial message:

https://www.spinics.net/lists/linux-scsi/msg102232.html

Upstream patch:

https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a0ac402cfcdc904f9772e1762b3fda112dcc56a0

Oss-security post:

http://seclists.org/oss-sec/2016/q4/644

Later an additional fix was developed, it was assigned CVE-2016-10088, see:

https://bugzilla.redhat.com/showbug.cgi?id=1412210

Red Hat

Affected Software

7 affected componentsFixes available
redhat/kernel<0:2.6.32-696.el6
0:2.6.32-696.el6
redhat/kernel-rt<0:3.10.0-693.rt56.617.el7
0:3.10.0-693.rt56.617.el7
redhat/kernel<0:3.10.0-693.el7
0:3.10.0-693.el7
redhat/kernel-rt<1:3.10.0-693.2.1.rt56.585.el6
1:3.10.0-693.2.1.rt56.585.el6
Linux Linux kernel>=4.0<4.4.38
Linux Linux kernel>=4.5<4.8.14
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-1

Event History

Nov 25, 2016
CVE Published
12:00 AM
Dec 9, 2016
Data Sourced
via Red Hat·08:40 AM
DescriptionSeverityAffected Software
Dec 28, 2016
CVE Published
via MITRE·07:42 AM
Data Sourced
via MITRE·07:42 AM
Description
Apr 28, 2025
Data Sourced
via Debian·03:32 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

Who is exposed to this issue?

Systems running affected Linux kernel versions with local users able to access /dev/sg* SCSI generic devices are exposed. The issue affects Linux kernels down to version 2.6 and kernels before 4.8.14.

2

What access does an attacker need?

An attacker needs local access and write access to a /dev/sg device. No user interaction is required.

3

What could exploitation allow?

Exploitation may allow reading from or writing to arbitrary kernel memory locations. It may also cause a denial of service through a use-after-free condition.

4

What should be done if patching cannot happen immediately?

Restrict local users' access, particularly write access, to /dev/sg* SCSI generic devices until a patched kernel can be deployed.

5

How can I determine whether a system is affected?

Check the running kernel version and whether local users can access /dev/sg* devices. Kernels before 4.8.14 are identified as affected in the provided information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203