CVE-2016-10154: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.

The smbhash function in fs/cifs/smbencrypt.c in the Linux kernel 4.9.x before 4.9.1 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a scatterlist.

Affected products

  • Linux Linux Kernel: version 4.9 only

Published 2017-02-06. Last modified 2026-06-17.