CVE-2016-9039

MEDIUM

Joyent SmartOS 20161110T013148Z - DoS

Title source: llm
STIX 2.1

Description

An exploitable denial of service exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES. An attacker can cause a buffer to be allocated and never freed. When repeatedly exploited this will result in memory exhaustion, resulting in a full system denial of service.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/95916
Exploit, Technical Description, Third Party Advisory, VDB Entry x_refsource_misc
http://www.talosintelligence.com/reports/TALOS-2016-0257/

Scores

CVSS v3 6.2
EPSS 0.0052
EPSS Percentile 40.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-400
Status published
Products (2)
joyent/smartos 20161110t013148z
Joyent/SmartOS OS 20161110T013148Z
Published Jan 31, 2017
Tracked Since Feb 18, 2026