PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-6866 Fedoraproject CVE debrief

CVE-2016-6866 describes a flaw in slock where an invalid password hash can trigger a NULL pointer dereference. The result is a crash with high availability impact, and the issue is described as allowing screen-lock bypass in the supplied corpus.

Vendor
Fedoraproject
Product
Unknown
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-15
Original CVE updated
2026-05-13
Advisory published
2017-02-15
Advisory updated
2026-05-13

Who should care

Administrators and users of suckless slock deployments, especially systems running vulnerable packaged builds such as the Fedora 24 and 25 references in the corpus.

Technical summary

NVD classifies the issue as CWE-476 (NULL pointer dereference) with CVSS 3.0 7.5/HIGH (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The affected CPE range includes suckless slock through version 1.3, and the supplied references point to upstream patch/advisory material, mailing list disclosure, and Fedora package announcements. The core security concern is that malformed authentication input can cause slock to crash and undermine the intended screen-lock behavior.

Defensive priority

High

Recommended defensive actions

  • Review whether any system uses suckless slock or a distribution package built from vulnerable sources.
  • Apply the upstream fix referenced by the vendor commit and install any distribution updates that incorporate it.
  • Confirm that patched builds still enforce the lock screen correctly after update.
  • Inventory Fedora 24/25 systems or other packaged deployments that may include the affected slock version range.
  • Treat repeated lock-screen crashes as a security incident and validate package provenance before redeployment.

Evidence notes

The supplied corpus includes the official CVE record, the NVD detail page, an upstream slock commit tagged as a patch/vendor advisory, an external advisory, Openwall disclosure threads, SecurityFocus, and Fedora package announcements. NVD lists CVSS 3.0: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H and CWE-476. The public reference material in the corpus dates to 2016-08-18, while the CVE publication date is 2017-02-15. No KEV entry is present in the supplied enrichment.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-6866 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-6866

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-6866 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-6866

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2FYPV6QQPPYBL3Z2BYNYEJB67FSC55OR/

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RZPEJQNVODYSI4WQXM5GQKXRO7TPK2VG/

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.