CVE-2016-9040
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An exploitable denial of service exists in the the Joyent SmartOS OS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFSADDENTRIES when used with a 32 bit model. An attacker can cause a buffer to be allocated and never freed. When repeatedly exploit this will result in memory exhaustion, resulting in a full system denial of service.
Existe una denegación de servicio (DoS) explotable en el sistema de archivos Hyprlofs de Joyent SmartOS OS 20161110T013148Z. La vulnerabilidad está presente en la llamada IOCTL del sistema con el comando HYPRLOFSADDENTRIES cuando se emplea con un modelo de 32 bits. Un atacante puede provocar que un búfer se asigne y no se libere nunca. Si se explota esto repetidamente, resultará en el agotamiento de la memoria y en una denegación de servicio (DoS) total del sistema.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-10-26 CVE Reserved
- 2018-09-07 CVE Published
- 2023-03-08 EPSS Updated
- 2024-09-16 CVE Updated
- 2024-09-16 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.talosintelligence.com/vulnerability_reports/TALOS-2016-0258 | 2024-09-16 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Joyent Search vendor "Joyent" | Smartos Search vendor "Joyent" for product "Smartos" | 20161110t013148z Search vendor "Joyent" for product "Smartos" and version "20161110t013148z" | - |
Affected
|