CVE-2002-2016 describes a critical vulnerability in User-mode Linux (UML) version 2.4.17-8, allowing local users to execute arbitrary code due to unrestricted access to the kernel address space. With a CVSS score of 7.2 (High) and a FAUCET Risk Score of 86/100, this flaw presents a significant risk, enabling complete compromise of confidentiality, integrity, and availability from a local attacker. While not on the KEV catalog and lacking Metasploit/Nuclei modules, an exploit is available on ExploitDB, indicating public knowledge of exploitation methods. Despite its age, the vulnerability has seen minimal community discussion and no media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4.17.8CPE matchmatch criteria | cpe:2.3:a:user-mode_linux:user-mode_linux:2.4.17.8:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.