Race condition in the ttyioctl function in drivers/tty/ttyio.c in the Linux kernel through 4.4.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (use-after-free and system crash) by making a TIOCGETD ioctl call during processing of a TIOCSETD ioctl call.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-0723.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "179205555145319643927839939308722981775",
"length": 2850.0
},
"signature_type": "Function",
"target": {
"file": "drivers/tty/tty_io.c",
"function": "tty_ioctl"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@5c17c861a357e9458001f021a7afa7aab9937439",
"id": "CVE-2016-0723-168df2f1",
"signature_version": "v1"
},
{
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"60460687664389241695412350078493385884",
"52241424085975488102673962496197507474",
"250935240338778645860390376808114623246",
"332540536078923742873804790459906520389",
"249787763824945592011078440899393320348",
"186716620297255816563682342021315134380",
"90585536843417055699613748253502060550"
]
},
"signature_type": "Line",
"target": {
"file": "drivers/tty/tty_io.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@5c17c861a357e9458001f021a7afa7aab9937439",
"id": "CVE-2016-0723-b87fc460",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-0723.json"
[
{
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"60460687664389241695412350078493385884",
"52241424085975488102673962496197507474",
"250935240338778645860390376808114623246",
"332540536078923742873804790459906520389",
"249787763824945592011078440899393320348",
"186716620297255816563682342021315134380",
"90585536843417055699613748253502060550"
]
},
"signature_type": "Line",
"target": {
"file": "drivers/tty/tty_io.c"
},
"source": "https://github.com/torvalds/linux/commit/5c17c861a357e9458001f021a7afa7aab9937439",
"id": "CVE-2016-0723-576acd1c",
"signature_version": "v1"
},
{
"deprecated": false,
"digest": {
"function_hash": "179205555145319643927839939308722981775",
"length": 2850.0
},
"signature_type": "Function",
"target": {
"file": "drivers/tty/tty_io.c",
"function": "tty_ioctl"
},
"source": "https://github.com/torvalds/linux/commit/5c17c861a357e9458001f021a7afa7aab9937439",
"id": "CVE-2016-0723-daacf3d5",
"signature_version": "v1"
}
]