[kernel-sec-discuss] r4983 - dsa-texts

Salvatore Bonaccorso carnil at moszumanska.debian.org
Wed Feb 22 10:17:15 UTC 2017


Author: carnil
Date: 2017-02-22 10:17:15 +0000 (Wed, 22 Feb 2017)
New Revision: 4983

Modified:
   dsa-texts/3.16.39-1+deb8u1
Log:
Add description for CVE-2016-9191

Modified: dsa-texts/3.16.39-1+deb8u1
===================================================================
--- dsa-texts/3.16.39-1+deb8u1	2017-02-22 09:37:57 UTC (rev 4982)
+++ dsa-texts/3.16.39-1+deb8u1	2017-02-22 10:17:15 UTC (rev 4983)
@@ -22,6 +22,11 @@
     information disclosure.
 
 CVE-2016-9191
+
+    CAI Qian discovered that reference counting is not properly handled
+    within proc_sys_readdir in the sysctl implementation, resulting in a
+    denial of service (system hang).
+
 CVE-2017-2583
 CVE-2017-2584
 CVE-2017-2596




More information about the kernel-sec-discuss mailing list