CVE-2016-1583 describes a local privilege escalation and denial-of-service vulnerability in the Linux kernel's ecryptfs_privileged_open function, affecting Canonical, Debian, Linux, and Novell distributions. This flaw allows a local attacker to gain elevated privileges or cause a system crash through crafted mmap calls on /proc pathnames, leading to recursive pagefault handling. Rated with a CVSS score of 7.8 (High), it has low attack complexity and can result in high impact to confidentiality, integrity, and availability. While not listed on the KEV catalog and with no observed active exploitation or significant community discussion, a public exploit (EDB-39992) exists, demonstrating its potential for abuse.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.19, < 3.18.54CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.19, < 4.4.14CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.5, < 4.6.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:a:novell:suse_linux_enterprise_software_development_kit:11.0:sp4:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:a:novell:suse_linux_enterprise_software_development_kit:12.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.