The filesystem layer in the Linux kernel before 4.5.5 proceeds with post-rename operations after an OverlayFS file is renamed to a self-hardlink, which allows local users to cause a denial of service (system crash) via a rename system call, related to fs/namei.c and fs/open.c.
{ "vanir_signatures": [ { "digest": { "length": 2710.0, "function_hash": "176251676786224064157905206971745351168" }, "signature_type": "Function", "deprecated": false, "source": "https://github.com/torvalds/linux/commit/9409e22acdfc9153f88d9b1ed2bd2a5b34d2d3ca", "target": { "function": "vfs_rename", "file": "fs/namei.c" }, "id": "CVE-2016-6198-0142c5ca", "signature_version": "v1" }, { "digest": { "threshold": 0.9, "line_hashes": [ "197257209627169793457663970201493696126" ] }, "signature_type": "Line", "deprecated": false, "source": "https://github.com/torvalds/linux/commit/54d5ca871e72f2bb172ec9323497f01cd5091ec7", "target": { "file": "include/linux/dcache.h" }, "id": "CVE-2016-6198-16d61762", "signature_version": "v1" }, { "digest": { "threshold": 0.9, "line_hashes": [ "89891878038560030249232699925676535603", "26312288617806036344930406045171254033", "248692019037616165390633097755433409283", "8961897124399606797207065396029946148", "165705065450177952252461897686553949462", "56323040694204037226334025255280940110", "222774412935605086779383760893235889121", "268083800110884528437775447158790556284", "125700114682384485847601627423199369279", "158141473186299625125714234304623700679", "153802846011920975573436258878695988367" ] }, "signature_type": "Line", "deprecated": false, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@54d5ca871e72f2bb172ec9323497f01cd5091ec7", "target": { "file": "fs/open.c" }, "id": "CVE-2016-6198-2e40c7a1", "signature_version": "v1" }, { "digest": { "threshold": 0.9, "line_hashes": [ "289056133303127936962192071689146772118", "5447575071570692459651203944272255256", "205673758122955577608367880640926876840", "15541864837550094388720007098781039363" ] }, "signature_type": "Line", "deprecated": false, "source": "https://github.com/torvalds/linux/commit/9409e22acdfc9153f88d9b1ed2bd2a5b34d2d3ca", "target": { "file": "fs/namei.c" }, "id": "CVE-2016-6198-917f3c4c", "signature_version": "v1" }, { "digest": { "length": 2710.0, "function_hash": "176251676786224064157905206971745351168" }, "signature_type": "Function", "deprecated": false, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@9409e22acdfc9153f88d9b1ed2bd2a5b34d2d3ca", "target": { "function": "vfs_rename", "file": "fs/namei.c" }, "id": "CVE-2016-6198-cb122903", "signature_version": "v1" }, { "digest": { "threshold": 0.9, "line_hashes": [ "197257209627169793457663970201493696126" ] }, "signature_type": "Line", "deprecated": false, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@54d5ca871e72f2bb172ec9323497f01cd5091ec7", "target": { "file": "include/linux/dcache.h" }, "id": "CVE-2016-6198-d5fb6c83", "signature_version": "v1" }, { "digest": { "threshold": 0.9, "line_hashes": [ "289056133303127936962192071689146772118", "5447575071570692459651203944272255256", "205673758122955577608367880640926876840", "15541864837550094388720007098781039363" ] }, "signature_type": "Line", "deprecated": false, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@9409e22acdfc9153f88d9b1ed2bd2a5b34d2d3ca", "target": { "file": "fs/namei.c" }, "id": "CVE-2016-6198-e4805007", "signature_version": "v1" }, { "digest": { "threshold": 0.9, "line_hashes": [ "89891878038560030249232699925676535603", "26312288617806036344930406045171254033", "248692019037616165390633097755433409283", "8961897124399606797207065396029946148", "165705065450177952252461897686553949462", "56323040694204037226334025255280940110", "222774412935605086779383760893235889121", "268083800110884528437775447158790556284", "125700114682384485847601627423199369279", "158141473186299625125714234304623700679", "153802846011920975573436258878695988367" ] }, "signature_type": "Line", "deprecated": false, "source": "https://github.com/torvalds/linux/commit/54d5ca871e72f2bb172ec9323497f01cd5091ec7", "target": { "file": "fs/open.c" }, "id": "CVE-2016-6198-eb1ca7f6", "signature_version": "v1" }, { "digest": { "length": 383.0, "function_hash": "212091280529959494568771255128061927971" }, "signature_type": "Function", "deprecated": false, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@54d5ca871e72f2bb172ec9323497f01cd5091ec7", "target": { "function": "vfs_open", "file": "fs/open.c" }, "id": "CVE-2016-6198-ed59507e", "signature_version": "v1" }, { "digest": { "length": 383.0, "function_hash": "212091280529959494568771255128061927971" }, "signature_type": "Function", "deprecated": false, "source": "https://github.com/torvalds/linux/commit/54d5ca871e72f2bb172ec9323497f01cd5091ec7", "target": { "function": "vfs_open", "file": "fs/open.c" }, "id": "CVE-2016-6198-fe57db5e", "signature_version": "v1" } ] }