The getrockridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have unspecified other impact via a crafted isofs filesystem.
{ "vanir_signatures": [ { "signature_type": "Line", "deprecated": false, "signature_version": "v1", "target": { "file": "fs/isofs/rock.c" }, "id": "CVE-2016-4913-1cbb8dbc", "digest": { "threshold": 0.9, "line_hashes": [ "161556957830916304382574331132987056051", "169376770444094046781879062078116260562", "155366834508113255007707426574280219691", "289789959570216607274820861410265973178", "296036237707224756809627538510757903067", "238733738201638695014100328463895396754", "129842957522589822821260136076391620207", "212527982907533936726619920637692303", "193044117044477666670130811826296320009", "185395606057069029366303601315246170759", "122526352989088855674382671908239300656", "254114191758853263376449489944409777893", "124625263443064793715919768453334574033" ] }, "source": "https://github.com/torvalds/linux/commit/99d825822eade8d827a1817357cbf3f889a552d6" }, { "signature_type": "Function", "deprecated": false, "signature_version": "v1", "target": { "file": "fs/isofs/rock.c", "function": "get_rock_ridge_filename" }, "id": "CVE-2016-4913-a5db8f79", "digest": { "length": 1598.0, "function_hash": "335732005652417979496417365694313319769" }, "source": "https://github.com/torvalds/linux/commit/99d825822eade8d827a1817357cbf3f889a552d6" }, { "signature_type": "Function", "deprecated": false, "signature_version": "v1", "target": { "file": "fs/isofs/rock.c", "function": "get_rock_ridge_filename" }, "id": "CVE-2016-4913-db0e0f19", "digest": { "length": 1598.0, "function_hash": "335732005652417979496417365694313319769" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@99d825822eade8d827a1817357cbf3f889a552d6" }, { "signature_type": "Line", "deprecated": false, "signature_version": "v1", "target": { "file": "fs/isofs/rock.c" }, "id": "CVE-2016-4913-f9869797", "digest": { "threshold": 0.9, "line_hashes": [ "161556957830916304382574331132987056051", "169376770444094046781879062078116260562", "155366834508113255007707426574280219691", "289789959570216607274820861410265973178", "296036237707224756809627538510757903067", "238733738201638695014100328463895396754", "129842957522589822821260136076391620207", "212527982907533936726619920637692303", "193044117044477666670130811826296320009", "185395606057069029366303601315246170759", "122526352989088855674382671908239300656", "254114191758853263376449489944409777893", "124625263443064793715919768453334574033" ] }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@99d825822eade8d827a1817357cbf3f889a552d6" } ] }