FlawAtlas
Search the atlas
UBUNTU-CVE-2016-8650 Moderate

UBUNTU-CVE-2016-8650

The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated for limb data, which allows local users to cause a denial of service (stack memory corruption and panic) via an add_key system call for an RSA key with a zero exponent.

Exploit probability Not scored
Published November 27, 2016
Required by Not available
Last source change April 22, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:14.04:LTS linux

120 explicit affected versions

Ubuntu:14.04:LTS linux-lts-xenial

20 explicit affected versions

Ubuntu:16.04:LTS linux

40 explicit affected versions

Ubuntu:16.04:LTS linux-aws

1 explicit affected versions

Ubuntu:16.04:LTS linux-hwe

1 explicit affected versions

Ubuntu:16.04:LTS linux-raspi2

19 explicit affected versions

Ubuntu:16.04:LTS linux-snapdragon

15 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related USN-3422-2

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2016-8650

The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated for limb data, which allows local users to cause a denial of service (stack memory corruption and panic) via an add_key system call for an RSA key with a zero exponent.

View original source

05 / REFERENCES

Further evidence