Race condition vulnerability in Linux kernel's tty_ioctl function allows local users to obtain sensitive information or cause a denial of service.

Race condition vulnerability in Linux kernel's tty_ioctl function allows local users to obtain sensitive information or cause a denial of service.

CVE-2016-0723 · MEDIUM Severity

AV:L/AC:L/AU:N/C:P/I:N/A:C

Race condition in the tty_ioctl function in drivers/tty/tty_io.c in the Linux kernel through 4.4.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (use-after-free and system crash) by making a TIOCGETD ioctl call during processing of a TIOCSETD ioctl call.

Learn more about our Cis Benchmark Audit For Distribution Independent Linux.