Medium severity5.5NVD Advisory· Published Nov 16, 2016· Updated May 6, 2026
CVE-2016-7916
CVE-2016-7916
Description
Race condition in the environ_read function in fs/proc/base.c in the Linux kernel before 4.5.4 allows local users to obtain sensitive information from kernel memory by reading a /proc/*/environ file during a process-setup time interval in which environment-variable copying is incomplete.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/nvdIssue TrackingPatchThird Party Advisory
- github.com/torvalds/linux/commit/8148a73c9901a8794a50f950083c00ccf97d43b3nvdIssue TrackingPatchThird Party Advisory
- source.android.com/security/bulletin/2016-11-01.htmlnvdThird Party Advisory
- www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.4nvdRelease NotesVendor Advisory
- www.securityfocus.com/bid/94138nvdThird Party AdvisoryVDB Entry
- bugzilla.kernel.org/show_bug.cginvdIssue Tracking
- forums.grsecurity.net/viewtopic.phpnvdIssue Tracking
- www.ubuntu.com/usn/USN-3159-1nvd
- www.ubuntu.com/usn/USN-3159-2nvd
News mentions
0No linked articles in our index yet.