Register for the AI for Security Summit: Join Figma, Perplexity & Wiz
Vulnerability DatabaseCVE-2016-1000253

CVE-2016-1000253
PHP vulnerability analysis and mitigation

Overview

CVE-2017-1000253 is a Linux kernel vulnerability affecting Position-Independent Executable (PIE) stack buffer handling. The vulnerability was discovered in the Linux kernel's load_elf_binary() function and was initially fixed in April 2015 but not recognized as a security threat at that time. The issue affects Linux distributions that had not patched their long-term kernels with the fix from kernel.org (NVD).

Technical details

The vulnerability occurs when CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE is enabled and using a normal top-down address allocation strategy. The load_elf_binary() function attempts to map a PIE binary into an address range immediately below mm->mmap_base but fails to account for the entire binary size. This results in the first PT_LOAD segment being mapped below mm->mmap_base, while subsequent PT_LOAD segments are incorrectly mapped above mm->mmap_base into the intended 'gap' between the stack and binary. The vulnerability has received a CVSS v3.1 Base Score of 7.8 (High) with vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (NVD).

Impact

The vulnerability can lead to local privilege escalation, potentially allowing attackers to gain unauthorized access to system resources. The high CVSS score indicates that successful exploitation could result in complete compromise of system confidentiality, integrity, and availability (NVD).

Exploitability

The vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation in the wild. CISA has set a remediation date of September 30, 2024, highlighting the urgency of addressing this vulnerability (CISA Alert).

Mitigation and workarounds

The vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 and was backported to Linux 3.10.77 in May 2015. Organizations are advised to apply vendor-provided patches or discontinue use of the product if mitigations are unavailable. CISA requires Federal Civilian Executive Branch (FCEB) agencies to remediate this vulnerability by September 30, 2024 (CISA Alert).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71537MEDIUM6.5
  • PHP logoPHP
  • paymenter/paymenter
NoYesSep 18, 2026
CVE-2026-77616MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026
CVE-2026-77610MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026
CVE-2026-77609MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026
CVE-2026-77608MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management