CVE-2016-9039
Last modified
CVE-2016-9039 is a vulnerability of currently unknown severity. An exploitable denial of service exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES. EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
An exploitable denial of service exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES. An attacker can cause a buffer to be allocated and never freed. When repeatedly exploited this will result in memory exhaustion, resulting in a full system denial of service.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Joyent | Smartos | 20161110t013148z |
References
- http://www.securityfocus.com/bid/95916Third Party Advisory, VDB Entry
- http://www.talosintelligence.com/reports/TALOS-2016-0257/Exploit, Technical Description, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/95916Third Party Advisory, VDB Entry
- http://www.talosintelligence.com/reports/TALOS-2016-0257/Exploit, Technical Description, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-9039?
How severe is CVE-2016-9039?
How do I fix CVE-2016-9039?
Are you affected by CVE-2016-9039?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
