Back

HIGH

kernel: Use after free vulnerability via double fdput

Published May 23, 2016

Description

The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly maintain an fd data structure, which allows local users to gain privileges or cause a denial of service (use-after-free) via crafted BPF instructions that reference an incorrect file descriptor.

Affected products

Remediation

Red Hat statement

This issue does not affect the Linux kernels as shipped with Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2.

Metrics

Weaknesses (1)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 23, 2016
Updated Aug 6, 2024
Reserved May 6, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Apr 26, 2016