Back

HIGH

kernel: Integer overflow in ring_buffer_resize()

Published Jan 5, 2017

Description

The ring_buffer_resize function in kernel/trace/ring_buffer.c in the profiling subsystem in the Linux kernel before 4.6.1 mishandles certain integer calculations, which allows local users to gain privileges by writing to the /sys/kernel/debug/tracing/buffer_size_kb file.

Affected products

Remediation

Red Hat statement

This issue does not affect the Linux kernels as shipped with Red Hat Enterprise Linux 5,6 and 7 kernels.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner google_android
Published Jan 5, 2017
Updated Aug 6, 2024
Reserved Dec 1, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date May 13, 2016