CVE-2016-9644
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
28/11/2016
Last modified:
12/04/2025
Description
The __get_user_asm_ex macro in arch/x86/include/asm/uaccess.h in the Linux kernel 4.4.22 through 4.4.28 contains extended asm statements that are incompatible with the exception table, which allows local users to obtain root access on non-SMEP platforms via a crafted application. NOTE: this vulnerability exists because of incorrect backporting of the CVE-2016-9178 patch to older kernels.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
9.30
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:4.4.22:*:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.4.23:*:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.4.24:*:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.4.25:*:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.4.26:*:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.4.27:*:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.4.28:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.openwall.com/lists/oss-security/2016/11/07/4
- http://www.securityfocus.com/bid/94545
- http://www.ubuntu.com/usn/USN-3146-1
- http://www.ubuntu.com/usn/USN-3146-2
- https://lwn.net/Articles/705220/
- http://www.openwall.com/lists/oss-security/2016/11/07/4
- http://www.securityfocus.com/bid/94545
- http://www.ubuntu.com/usn/USN-3146-1
- http://www.ubuntu.com/usn/USN-3146-2
- https://lwn.net/Articles/705220/



