Back

MEDIUM

kernel: Race condition vulnerability in Chrome driver

Published Aug 6, 2016

Description

Race condition in the ec_device_ioctl_xcmd function in drivers/platform/chrome/cros_ec_dev.c in the Linux kernel before 4.7 allows local users to cause a denial of service (out-of-bounds array access) by changing a certain size value, aka a "double fetch" vulnerability.

Affected products

Remediation

Red Hat statement

This issue does not affect Red Hat Enterprise Linux products as they have not included this feature in any shipping products.

Metrics

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 6, 2016
Updated Aug 6, 2024
Reserved Jul 1, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 4, 2016