CVE-2016-1583: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 1.4% chance of exploitation in the next 30 days.
The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted mmap calls for /proc pathnames, leading to recursive pagefault handling.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only; version 16.04 only
- Debian Debian Linux: version 8.0 only
- Linux Linux Kernel: from 2.6.19, before 3.18.54 (fixed in 3.18.54); from 3.19, before 4.4.14 (fixed in 4.4.14); from 4.5, before 4.6.3 (fixed in 4.6.3)
- Novell Suse Linux Enterprise Debuginfo: version 11.0 only
- Novell Suse Linux Enterprise Desktop: version 12.0 only
- Novell Suse Linux Enterprise Live Patching: version 12.0 only
- Novell Suse Linux Enterprise Module For Public Cloud: version 12 only
- Novell Suse Linux Enterprise Server: version 11.0 only; version 12.0 only
- Novell Suse Linux Enterprise Software Development Kit: version 11.0 only; version 12.0 only
- Novell Suse Linux Enterprise Workstation Extension: version 12.0 only
Published 2016-06-27. Last modified 2026-06-17.