CVE

Id
93938  
CVE No.
CVE-2016-7118  
Status
Candidate  
Description
fs/fcntl.c in the "aufs 3.2.x+setfl-debian" patch in the linux-image package 3.2.0-4 (kernel 3.2.81-1) in Debian wheezy mishandles F_SETFL fcntl calls on directories, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via standard filesystem operations, as demonstrated by scp from an AUFS filesystem.  
Phase
Assigned (20160831)  
Votes
None (candidate not yet proposed)  
Comments