CVE-2016-6198

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
06/08/2016
Last modified:
12/04/2025

Description

The filesystem layer in the Linux kernel before 4.5.5 proceeds with post-rename operations after an OverlayFS file is renamed to a self-hardlink, which allows local users to cause a denial of service (system crash) via a rename system call, related to fs/namei.c and fs/open.c.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.5.4 (including)
cpe:2.3:o:oracle:linux:6:*:*:*:*:*:*:*
cpe:2.3:a:oracle:vm_server:3.4:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools