Vulnerability record · CVE-2016-8733 · published 14 December 2016
CVE-2016-8733: Joyent smartos integer overflow vulnerability
JJoyent · Smartos
An exploitable integer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES when dealing with native file systems. An attacker can craft an input that can cause a kernel panic and potentially be leveraged into a full privilege escalation vulnerability. This vulnerability is distinct from CVE-2016-9031.
Description
An exploitable integer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES when dealing with native file systems. An attacker can craft an input that can cause a kernel panic and potentially be leveraged into a full privilege escalation vulnerability. This vulnerability is distinct from CVE-2016-9031.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/94920 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.talosintelligence.com/reports/TALOS-2016-0248/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/94920 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.talosintelligence.com/reports/TALOS-2016-0248/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2016-8733 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-8733), CISA KEV, FIRST EPSS (scores of 2026-10-04). This page is refreshed as NVD updates the record.