CVE-2016-4913: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have unspecified other impact via a crafted isofs filesystem.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only; version 16.04 only
  • Linux Linux Kernel: before 3.2.81 (fixed in 3.2.81); from 3.3, before 3.10.102 (fixed in 3.10.102); from 3.11, before 3.12.60 (fixed in 3.12.60); from 3.13, before 3.14.70 (fixed in 3.14.70); from 3.15, before 3.16.36 (fixed in 3.16.36); from 3.17, before 3.18.34 (fixed in 3.18.34); …
  • Novell Suse Linux Enterprise Debuginfo: version 11.0 only
  • Novell Suse Linux Enterprise Server: version 11.0 only
  • Novell Suse Linux Enterprise Software Development Kit: version 11.0 only
  • Oracle Linux: version 6 only

Published 2016-05-23. Last modified 2026-06-17.