CVE-2016-5728

MEDIUM

Linux kernel <4.6.1 - Info Disclosure

Title source: llm

Description

Race condition in the vop_ioctl function in drivers/misc/mic/vop/vop_vringh.c in the MIC VOP driver in the Linux kernel before 4.6.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (memory corruption and system crash) by changing a certain header, aka a "double fetch" vulnerability.

Scores

CVSS v3 6.3
EPSS 0.0006
EPSS Percentile 19.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H

Classification

CWE
CWE-119
Status draft

Affected Products (2)

debian/debian_linux
linux/linux_kernel < 4.6

Timeline

Published Jun 27, 2016
Tracked Since Feb 18, 2026