Description
fs/ext4/inode.c in the Linux kernel before 4.6.2, when ext4 data=ordered mode is used, mishandles a needs-flushing-before-commit list, which allows local users to obtain sensitive information from other users' files in opportunistic circumstances by waiting for a hardware reset, creating a new file, making write system calls, and reading this file.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-16512 | fs/ext4/inode.c in the Linux kernel before 4.6.2, when ext4 data=ordered mode is used, mishandles a needs-flushing-before-commit list, which allows local users to obtain sensitive information from other users' files in opportunistic circumstances by waiting for a hardware reset, creating a new file, making write system calls, and reading this file. |
Ubuntu USN |
USN-3405-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3405-2 | Linux kernel (Xenial HWE) vulnerabilities |
Ubuntu USN |
USN-3406-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3406-2 | Linux kernel (Trusty HWE) vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T16:04:11.875Z
Reserved: 2017-04-05T00:00:00.000Z
Link: CVE-2017-7495
No data.
Status : Modified
Published: 2017-05-15T18:29:00.373
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-7495
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN