CVE-2016-10154 is a denial-of-service vulnerability affecting the Linux kernel versions 4.9.x before 4.9.1. It stems from an incorrect interaction between the smbhash function and the CONFIG_VMAP_STACK option, allowing local users to trigger a system crash or memory corruption. Rated Medium severity (CVSS 5.5), this vulnerability requires local access and low attack complexity. Its primary impact is a denial of service, though other unspecified impacts are possible. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.9CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:4.9:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.