CVE-2016-9039
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An exploitable denial of service exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES. An attacker can cause a buffer to be allocated and never freed. When repeatedly exploited this will result in memory exhaustion, resulting in a full system denial of service.
Existe una denegación de servicio explotable en el sistema de archivos Hyprlofs de Joyent SmartOS 20161110T013148Z. La vulnerabilidad está presente en la llamada al sistema Ioctl con el comando HYPRLOFS_ADD_ENTRIES. Un atacante puede hacer que se asigne un búfer y nunca se libere. Cuando se explota repetidamente esto resultará en el agotamiento de la memoria, resultando en una denegación de servicio del sistema completo
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-10-26 CVE Reserved
- 2017-01-31 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/95916 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
http://www.talosintelligence.com/reports/TALOS-2016-0257 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Joyent Search vendor "Joyent" | Smartos Search vendor "Joyent" for product "Smartos" | 20161110t013148z Search vendor "Joyent" for product "Smartos" and version "20161110t013148z" | - |
Affected
|