CVE-2016-4565
HighThe InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI interface.
CVSS 3.1 score
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness type
CWE-264CVE-2016-4565 is a Permissions, Privileges and Access Control vulnerability
What is Permissions, Privileges and Access Control?
Weaknesses in this category are related to the management of permissions, privileges, and access controls. Learn more on MITRE CWE
References
The following references provide additional information about CVE-2016-4565 including vendor advisories, patch commits, exploit details, and third-party analysis. Links are sourced from the NIST NVD database.
-
Mailing List Third Party Advisory
-
Mailing List Third Party Advisory
-
Mailing List Third Party Advisory
-
Mailing List Third Party Advisory
-
Mailing List Third Party Advisory
-
Mailing List Third Party Advisory
-
Mailing List Third Party Advisory
-
Mailing List Third Party Advisory
-
Mailing List Third Party Advisory
-
Mailing List Third Party Advisory
-
Mailing List Third Party Advisory
-
Mailing List Third Party Advisory
-
Mailing List Third Party Advisory
-
Mailing List Third Party Advisory
-
Mailing List Third Party Advisory
-
Mailing List Third Party Advisory
-
Mailing List Third Party Advisory
-
Mailing List Third Party Advisory
-
Mailing List Third Party Advisory
-
Mailing List Third Party Advisory
-
Mailing List Third Party Advisory
-
Third Party Advisory
-
Third Party Advisory
-
Third Party Advisory
-
Third Party Advisory
-
Third Party Advisory
-
Third Party Advisory
-
Debian Securityhttp://www.debian.org/security/2016/dsa-3607Third Party Advisory
-
Vendor Advisory
-
Mailing List Third Party Advisory
-
Third Party Advisory
-
Third Party Advisory
-
Third Party Advisory
-
Securityfocushttp://www.securityfocus.com/bid/90301Third Party Advisory VDB Entry
-
Ubuntu Securityhttp://www.ubuntu.com/usn/USN-3001-1Third Party Advisory
-
Ubuntu Securityhttp://www.ubuntu.com/usn/USN-3002-1Third Party Advisory
-
Ubuntu Securityhttp://www.ubuntu.com/usn/USN-3003-1Third Party Advisory
-
Ubuntu Securityhttp://www.ubuntu.com/usn/USN-3004-1Third Party Advisory
-
Ubuntu Securityhttp://www.ubuntu.com/usn/USN-3005-1Third Party Advisory
-
Ubuntu Securityhttp://www.ubuntu.com/usn/USN-3006-1Third Party Advisory
-
Ubuntu Securityhttp://www.ubuntu.com/usn/USN-3007-1Third Party Advisory
-
Ubuntu Securityhttp://www.ubuntu.com/usn/USN-3018-1Third Party Advisory
-
Ubuntu Securityhttp://www.ubuntu.com/usn/USN-3018-2Third Party Advisory
-
Ubuntu Securityhttp://www.ubuntu.com/usn/USN-3019-1Third Party Advisory
-
Ubuntu Securityhttp://www.ubuntu.com/usn/USN-3021-1Third Party Advisory
-
Ubuntu Securityhttp://www.ubuntu.com/usn/USN-3021-2Third Party Advisory
-
Third Party Advisory
-
Third Party Advisory
-
Third Party Advisory
-
Third Party Advisory
-
Issue Tracking Third Party Advisory
-
PatchKernel patch commithttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e6bd18f57aad1a2d1ef40e646d03ed0f2515c9e3
-
PatchKernel patch commithttps://github.com/torvalds/linux/commit/e6bd18f57aad1a2d1ef40e646d03ed0f2515c9e3
Frequently asked questions
-
What is CVE-2016-4565?
CVE-2016-4565 is a High severity Linux kernel vulnerability with a CVSS score of 7.8 out of 10 , classified as a Permissions, Privileges and Access Control flaw (CWE-264) . CVE-2016-4565 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
What is the CVSS score for CVE-2016-4565?
CVE-2016-4565 has a CVSS score of 7.8 out of 10, rated High severity (CVSS 3.1). The vector string is
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. -
Is there a patch available for CVE-2016-4565?
No patch is currently available for CVE-2016-4565. Monitor the NIST NVD and your Linux distribution's security advisories for updates.
-
Is CVE-2016-4565 actively exploited?
No — CVE-2016-4565 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
-
What is Permissions, Privileges and Access Control (CWE-264)?
Weaknesses in this category are related to the management of permissions, privileges, and access controls. View CWE-264 on MITRE CWE →