CVE-2016-0723

medium
Published 2016-02-08 · Modified 2026-05-06
CVSS v3
6.8
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
CVSS v2
5.6
VIR risk
6.8

Description

Race condition in the tty_ioctl function in drivers/tty/tty_io.c in the Linux kernel through 4.4.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (use-after-free and system crash) by making a TIOCGETD ioctl call during processing of a TIOCSETD ioctl call.

Predictions

Exploit likelihood
67%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-0723

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=5c17c861a357e9458001f021a7afa7aab9937439

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2016-0723.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed4.3.3-6
debian debianbullseyefixed4.3.3-6
debian debianforkyfixed4.3.3-6
debian debiansidfixed4.3.3-6
debian debiantrixiefixed4.3.3-6
linux linux-kernelaffected

References

CWEs

CWE-200 CWE-362

Verify integrity in audit chain (admin only). AS-IS.