CVE-2016-9039

An exploitable denial of service exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES. An attacker can cause a buffer to be allocated and never freed. When repeatedly exploited this will result in memory exhaustion, resulting in a full system denial of service.
References
Link Resource
http://www.securityfocus.com/bid/95916 Third Party Advisory VDB Entry
http://www.talosintelligence.com/reports/TALOS-2016-0257/ Exploit Technical Description Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:o:joyent:smartos:20161110t013148z:*:*:*:*:*:*:*

History

19 Apr 2022, 20:15

Type Values Removed Values Added
Summary An exploitable denial of service exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES. An attacker can cause a buffer to be allocated and never freed. When repeatedly exploited this will result in memory exhaustion, resulting in a full system denial of service. An exploitable denial of service exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES. An attacker can cause a buffer to be allocated and never freed. When repeatedly exploited this will result in memory exhaustion, resulting in a full system denial of service.

Information

Published : 2017-01-31 21:59

Updated : 2023-12-10 12:01


NVD link : CVE-2016-9039

Mitre link : CVE-2016-9039

CVE.ORG link : CVE-2016-9039


JSON object : View

Products Affected

joyent

  • smartos
CWE
CWE-400

Uncontrolled Resource Consumption