CVE-2016-6197

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
06/08/2016
Last modified:
12/04/2025

Description

fs/overlayfs/dir.c in the OverlayFS filesystem implementation in the Linux kernel before 4.6 does not properly verify the upper dentry before proceeding with unlink and rename system-call processing, which allows local users to cause a denial of service (system crash) via a rename system call that specifies a self-hardlink.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:oracle:linux:6:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.5.7 (including)
cpe:2.3:o:oracle:vm_server:3.4:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools