Race condition in the auditlogsingleexecvearg function in kernel/auditsc.c in the Linux kernel through 4.7 allows local users to bypass intended character-set restrictions or disrupt system-call auditing by changing a certain string, aka a "double fetch" vulnerability.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-6136.json"
[
{
"id": "CVE-2016-6136-21115056",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@43761473c254b45883a64441dd0bc85a42f3645c",
"target": {
"file": "kernel/auditsc.c",
"function": "audit_log_execve_info"
},
"digest": {
"function_hash": "194152817263724175772579838245103535386",
"length": 551.0
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function"
},
{
"id": "CVE-2016-6136-9f14280e",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@43761473c254b45883a64441dd0bc85a42f3645c",
"target": {
"file": "kernel/auditsc.c",
"function": "audit_log_single_execve_arg"
},
"digest": {
"function_hash": "17657156754217856690856200517224487297",
"length": 1845.0
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function"
},
{
"id": "CVE-2016-6136-e807069f",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@43761473c254b45883a64441dd0bc85a42f3645c",
"target": {
"file": "kernel/auditsc.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"327736379005300463002968294500431273211",
"311115362355518982843515717454621598143",
"152449997580257414064616150407668519824",
"297315614152721254590784115182352795105",
"264627988666320132871899899594515610004",
"86670015631482635499528250519376161075",
"74932356571111606231049029206716939195",
"12676454801171218335652512862979622229",
"292796500242852128774277640607272474988",
"120114611985024278902779922881633409706",
"181149513841041275154977811709675187053",
"212677705233259048471308665919112313771",
"11568257545553135410431638594282168569",
"220695311010110697374450694726624483462",
"163062143999235594115276850092309837551",
"250009738115594712411958148766248841978",
"236641256649745728810781471804142397754",
"7821970469660067846202842429967188288",
"196125082342483891905441634304254341499",
"318160954525422429240989691352017590872",
"26353824365147555577405913511431478381",
"25069482147927997244127567121072742661",
"7611990434960231915659286215855260791",
"222514494882981123497015322595794709034",
"118210720295892294138364107936786268923",
"266690633226996308932187876859958776120",
"146980492556492384523283709867323568355",
"181312347931132766036885712911462252456",
"87520863062706306517986559389517558171",
"248276175365635109977138316374369702289",
"68094701413269513897568518909206757311",
"283213687591024223414371870728387429166",
"194349644515368817543401412615105519536",
"306289761874523693394287539252596597138",
"132516777046215228020852673480957267704",
"21592162083465255013441182772521600804",
"177126370308049129095893431278616706346",
"232979725491787985636785863751412523",
"38100533592171003263189379161323594938",
"261782575598088917100168756619120446962",
"60996718035332342525073352933364728116",
"238134129746983018042379598387562244617",
"53014145466089215163461430642807954127",
"204069725259187530888277450274591525128",
"270532169453468373388329752869276433781",
"224670820236717756779025737250537638587",
"7445467827323024687706120669256597799",
"33577556951625150382270352640059490166",
"338999878180189634895502714565148018329",
"157755623553750101274772465840388232120",
"46854647496958335249020264272041733196",
"258397238272230098291652970703286914304",
"223943927084642175749206838673519700953",
"248276175365635109977138316374369702289",
"212103965824021912241282154277735235058",
"145919776558085251710336646226680967737",
"76639146803216547866245783263106349815",
"130659186652204837531379049252517022689",
"92298083131450432203050529128575240952",
"319340456317605215022575432760495026993",
"10050239780159016222578632395472071221",
"258990748931010545669811692101500713094",
"160427766778798543957649183051726581068",
"73229140454095197908992947781393411253",
"83622753713769473298763429307736226047",
"312589833398138693085755169614607555099",
"75297937920418987406161072556533590566",
"309605490449360652155584198669135557459",
"196189904731340920691796420382253637600",
"59271411063394197102145273390829412941",
"152597894196108971556396158576143158427",
"161730515756581053339910874364819619708",
"328924782831088979522792343045652444001",
"43482164626357042084396519186625679501",
"242697895492346702724955216576859975478",
"40834250557115954330252187398252719075",
"132516777046215228020852673480957267704",
"21592162083465255013441182772521600804",
"177126370308049129095893431278616706346",
"25407886263447073578775839997343082014",
"147236205231259503132979518928744271686",
"156785637073254657353360913605801752067",
"203743873285356645348822741793803316264",
"66023299153712608670637859528688264162",
"76953068273007327177979750819364976377",
"16199812441199541673913160147790776875",
"113741720484134915672824474257155509178",
"271429759507614179964383923070655732975",
"247314942276746233141506666539326147204",
"272048807538473981326791440149733411500",
"76664727973564227313636077945130439733",
"269604194662978516242144781453402435915",
"27866554771069487434474005387022172284",
"101979911996330550998206594513602827023",
"136051255411649107915924262569377323750",
"34785579871557255551888176498769479574",
"1384781980025766178179787929943356138",
"59613343927142346867888127097709039570",
"299683730816729891543941243658208460524",
"156877234364558559358431626275207469704",
"310126641488672839124088446242585931741",
"9703392013768656716249880528410647150",
"283347529159302970625907084986490989009",
"185364755121175765053391292512452774224",
"336158597482871707999460459556016795226",
"253331280337827753392823655141601739327",
"238393132733585456885026905409551945448",
"326345968958258830392866448156186291962",
"139596269401328556323740906470137498315",
"255313506050697828893669101138958483845",
"183922596903658652398907200972237832829",
"217658635316960563172081758361049538756",
"312397240024206161374349091516152844489",
"20607866897920380706327364101850716925",
"132642836026525054383065058392071857701",
"238601426199229162301618259006274872441",
"230013037264024105670756814711865807331",
"294430767775598805134671624670462954173",
"246389558251165975394504970966237229189",
"73877812904144131541090394372514927864",
"113526816836083369969458156108185119037",
"321000257909873240773933836653830579827"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-6136.json"
[
{
"id": "CVE-2016-6136-6770d170",
"source": "https://github.com/torvalds/linux/commit/43761473c254b45883a64441dd0bc85a42f3645c",
"target": {
"file": "kernel/auditsc.c",
"function": "audit_log_execve_info"
},
"digest": {
"function_hash": "194152817263724175772579838245103535386",
"length": 551.0
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function"
},
{
"id": "CVE-2016-6136-72687bdb",
"source": "https://github.com/torvalds/linux/commit/43761473c254b45883a64441dd0bc85a42f3645c",
"target": {
"file": "kernel/auditsc.c",
"function": "audit_log_single_execve_arg"
},
"digest": {
"function_hash": "17657156754217856690856200517224487297",
"length": 1845.0
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function"
},
{
"id": "CVE-2016-6136-f8a8f014",
"source": "https://github.com/torvalds/linux/commit/43761473c254b45883a64441dd0bc85a42f3645c",
"target": {
"file": "kernel/auditsc.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"327736379005300463002968294500431273211",
"311115362355518982843515717454621598143",
"152449997580257414064616150407668519824",
"297315614152721254590784115182352795105",
"264627988666320132871899899594515610004",
"86670015631482635499528250519376161075",
"74932356571111606231049029206716939195",
"12676454801171218335652512862979622229",
"292796500242852128774277640607272474988",
"120114611985024278902779922881633409706",
"181149513841041275154977811709675187053",
"212677705233259048471308665919112313771",
"11568257545553135410431638594282168569",
"220695311010110697374450694726624483462",
"163062143999235594115276850092309837551",
"250009738115594712411958148766248841978",
"236641256649745728810781471804142397754",
"7821970469660067846202842429967188288",
"196125082342483891905441634304254341499",
"318160954525422429240989691352017590872",
"26353824365147555577405913511431478381",
"25069482147927997244127567121072742661",
"7611990434960231915659286215855260791",
"222514494882981123497015322595794709034",
"118210720295892294138364107936786268923",
"266690633226996308932187876859958776120",
"146980492556492384523283709867323568355",
"181312347931132766036885712911462252456",
"87520863062706306517986559389517558171",
"248276175365635109977138316374369702289",
"68094701413269513897568518909206757311",
"283213687591024223414371870728387429166",
"194349644515368817543401412615105519536",
"306289761874523693394287539252596597138",
"132516777046215228020852673480957267704",
"21592162083465255013441182772521600804",
"177126370308049129095893431278616706346",
"232979725491787985636785863751412523",
"38100533592171003263189379161323594938",
"261782575598088917100168756619120446962",
"60996718035332342525073352933364728116",
"238134129746983018042379598387562244617",
"53014145466089215163461430642807954127",
"204069725259187530888277450274591525128",
"270532169453468373388329752869276433781",
"224670820236717756779025737250537638587",
"7445467827323024687706120669256597799",
"33577556951625150382270352640059490166",
"338999878180189634895502714565148018329",
"157755623553750101274772465840388232120",
"46854647496958335249020264272041733196",
"258397238272230098291652970703286914304",
"223943927084642175749206838673519700953",
"248276175365635109977138316374369702289",
"212103965824021912241282154277735235058",
"145919776558085251710336646226680967737",
"76639146803216547866245783263106349815",
"130659186652204837531379049252517022689",
"92298083131450432203050529128575240952",
"319340456317605215022575432760495026993",
"10050239780159016222578632395472071221",
"258990748931010545669811692101500713094",
"160427766778798543957649183051726581068",
"73229140454095197908992947781393411253",
"83622753713769473298763429307736226047",
"312589833398138693085755169614607555099",
"75297937920418987406161072556533590566",
"309605490449360652155584198669135557459",
"196189904731340920691796420382253637600",
"59271411063394197102145273390829412941",
"152597894196108971556396158576143158427",
"161730515756581053339910874364819619708",
"328924782831088979522792343045652444001",
"43482164626357042084396519186625679501",
"242697895492346702724955216576859975478",
"40834250557115954330252187398252719075",
"132516777046215228020852673480957267704",
"21592162083465255013441182772521600804",
"177126370308049129095893431278616706346",
"25407886263447073578775839997343082014",
"147236205231259503132979518928744271686",
"156785637073254657353360913605801752067",
"203743873285356645348822741793803316264",
"66023299153712608670637859528688264162",
"76953068273007327177979750819364976377",
"16199812441199541673913160147790776875",
"113741720484134915672824474257155509178",
"271429759507614179964383923070655732975",
"247314942276746233141506666539326147204",
"272048807538473981326791440149733411500",
"76664727973564227313636077945130439733",
"269604194662978516242144781453402435915",
"27866554771069487434474005387022172284",
"101979911996330550998206594513602827023",
"136051255411649107915924262569377323750",
"34785579871557255551888176498769479574",
"1384781980025766178179787929943356138",
"59613343927142346867888127097709039570",
"299683730816729891543941243658208460524",
"156877234364558559358431626275207469704",
"310126641488672839124088446242585931741",
"9703392013768656716249880528410647150",
"283347529159302970625907084986490989009",
"185364755121175765053391292512452774224",
"336158597482871707999460459556016795226",
"253331280337827753392823655141601739327",
"238393132733585456885026905409551945448",
"326345968958258830392866448156186291962",
"139596269401328556323740906470137498315",
"255313506050697828893669101138958483845",
"183922596903658652398907200972237832829",
"217658635316960563172081758361049538756",
"312397240024206161374349091516152844489",
"20607866897920380706327364101850716925",
"132642836026525054383065058392071857701",
"238601426199229162301618259006274872441",
"230013037264024105670756814711865807331",
"294430767775598805134671624670462954173",
"246389558251165975394504970966237229189",
"73877812904144131541090394372514927864",
"113526816836083369969458156108185119037",
"321000257909873240773933836653830579827"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line"
}
]