Medium severity4.3NVD Advisory· Published Feb 6, 2017· Updated Jun 17, 2026
CVE-2016-10208
CVE-2016-10208
Description
The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.9.8 does not properly validate meta block groups, which allows physically proximate attackers to cause a denial of service (out-of-bounds read and system crash) via a crafted ext4 image.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
29- osv-coords27 versionspkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP1pkg:rpm/suse/kernel-docs&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1pkg:rpm/suse/kernel-ec2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2012pkg:rpm/suse/kernel-obs-build&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/kernel-xen&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/kernel-xen&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/kernel-xen&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/kernel-xen&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012pkg:rpm/suse/kernel-xen&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/kgraft-patch-SLE12-SP1_Update_15&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2012pkg:rpm/suse/kgraft-patch-SLE12_Update_21&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/kgraft-patch-SLE12_Update_21&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012
< 3.12.74-60.64.40.1+ 26 more
- (no CPE)range: < 3.12.74-60.64.40.1
- (no CPE)range: < 3.12.74-60.64.40.1
- (no CPE)range: < 3.12.61-52.72.1
- (no CPE)range: < 3.12.61-52.72.1
- (no CPE)range: < 3.12.74-60.64.40.1
- (no CPE)range: < 3.12.74-60.64.40.1
- (no CPE)range: < 3.12.74-60.64.40.4
- (no CPE)range: < 3.12.61-52.72.1
- (no CPE)range: < 3.12.74-60.64.40.1
- (no CPE)range: < 3.12.74-60.64.40.1
- (no CPE)range: < 3.12.74-60.64.40.1
- (no CPE)range: < 3.12.61-52.72.1
- (no CPE)range: < 3.12.61-52.72.1
- (no CPE)range: < 3.12.74-60.64.40.1
- (no CPE)range: < 3.12.74-60.64.40.1
- (no CPE)range: < 3.12.74-60.64.40.1
- (no CPE)range: < 3.12.61-52.72.1
- (no CPE)range: < 3.12.61-52.72.1
- (no CPE)range: < 3.12.74-60.64.40.1
- (no CPE)range: < 3.12.74-60.64.40.1
- (no CPE)range: < 3.12.74-60.64.40.1
- (no CPE)range: < 3.12.61-52.72.1
- (no CPE)range: < 3.12.61-52.72.1
- (no CPE)range: < 3.12.74-60.64.40.1
- (no CPE)range: < 1-4.1
- (no CPE)range: < 1-2.1
- (no CPE)range: < 1-2.1
Patches
Vulnerability mechanics
References
11- git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/nvdIssue TrackingPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2017/02/05/3nvdMailing ListPatchThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatch
- github.com/torvalds/linux/commit/3a4b77cd47bb837b8557595ec7425f281f2ca1fenvdIssue TrackingPatchThird Party Advisory
- seclists.org/fulldisclosure/2016/Nov/75nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/94354nvd
- access.redhat.com/errata/RHSA-2017:1297nvd
- access.redhat.com/errata/RHSA-2017:1298nvd
- access.redhat.com/errata/RHSA-2017:1308nvd
- lists.debian.org/debian-lts-announce/2017/12/msg00004.htmlnvd
- usn.ubuntu.com/3754-1/nvd
News mentions
0No linked articles in our index yet.