CVE-2016-9685: Medium severity linux kernel vulnerability
A flaw was found in the Linux kernels implementation of XFS file attributes. Two memory leaks were detected in xfsattrshortformlist and xfsattr3leaflistint when running a docker container backed by xfs/overlay2. A dedicated attacker could possible exhaust all memory and create a denial of service situation.
Product bug:
https://bugzilla.redhat.com/showbug.cgi?id=1391223
OSS-Security post: http://seclists.org/oss-sec/2016/q4/544
Other sources
Multiple memory leaks in error paths in fs/xfs/xfsattrlist.c in the Linux kernel before 4.5.1 allow local users to cause a denial of service (memory consumption) via crafted XFS filesystem operations.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability CVE-2016-9685?
Multiple memory leaks in error paths in fs/xfs/xfs_attr_list.c in the Linux kernel before 4.5.1 allow local users to cause a denial of service (memory consumption) via crafted XFS filesystem operations.
Which software versions are affected by CVE-2016-9685?
The vulnerability affects Linux kernel versions before 4.5.1.
What is the severity of CVE-2016-9685?
The severity of CVE-2016-9685 is low.
How can I fix CVE-2016-9685?
To fix CVE-2016-9685, update your Linux kernel to version 4.5.1 or later.
Where can I find more information about CVE-2016-9685?
You can find more information about CVE-2016-9685 at the following references: [Link 1](http://www.openwall.com/lists/oss-security/2016/11/30/1), [Link 2](http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2e83b79b2d6c78bf1b4aa227938a214dcbddc83f), [Link 3](http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.1).