CVE-2016-0723

MEDIUM

Linux kernel <4.4.1 - Info Disclosure/DoS

Title source: llm

Description

Race condition in the tty_ioctl function in drivers/tty/tty_io.c in the Linux kernel through 4.4.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (use-after-free and system crash) by making a TIOCGETD ioctl call during processing of a TIOCSETD ioctl call.

References (29)

... and 9 more

Scores

CVSS v3 6.8
EPSS 0.0003
EPSS Percentile 6.7%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

Classification

CWE
CWE-362 CWE-200
Status draft

Affected Products (1)

linux/linux_kernel < 4.4.1

Timeline

Published Feb 08, 2016
Tracked Since Feb 18, 2026