The aiomount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which makes it easier for local users to bypass intended SELinux W^X policy restrictions, and consequently gain privileges, via an iosetup system call.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-10044.json"
[
{
"id": "CVE-2016-10044-2e70984b",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@22f6b4d34fcf039c63a94e7670e0da24f8575a5a",
"target": {
"file": "fs/aio.c",
"function": "aio_mount"
},
"digest": {
"function_hash": "83210589232738122149611581927273019036",
"length": 224.0
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function"
},
{
"id": "CVE-2016-10044-94d2cdd5",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@22f6b4d34fcf039c63a94e7670e0da24f8575a5a",
"target": {
"file": "fs/aio.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"60224599636767662768645366123764715115",
"183452556749183586084820303336239319253",
"307036466636147671524075887034633250006",
"15138847296877836060536222162345377098"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-10044.json"
[
{
"id": "CVE-2016-10044-9e0f9ec7",
"source": "https://github.com/torvalds/linux/commit/22f6b4d34fcf039c63a94e7670e0da24f8575a5a",
"target": {
"file": "fs/aio.c",
"function": "aio_mount"
},
"digest": {
"function_hash": "83210589232738122149611581927273019036",
"length": 224.0
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function"
},
{
"id": "CVE-2016-10044-d4a1fe6e",
"source": "https://github.com/torvalds/linux/commit/22f6b4d34fcf039c63a94e7670e0da24f8575a5a",
"target": {
"file": "fs/aio.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"60224599636767662768645366123764715115",
"183452556749183586084820303336239319253",
"307036466636147671524075887034633250006",
"15138847296877836060536222162345377098"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line"
}
]