Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-2383

Опубликовано: 27 апр. 2016
Источник: debian
EPSS Низкий

Описание

The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the backward-jump case, which allows local users to obtain sensitive information from kernel memory by creating a packet filter and then loading crafted BPF instructions.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed4.4.2-1package
linuxnot-affectedjessiepackage
linuxnot-affectedwheezypackage
linux-2.6not-affectedpackage

Примечания

  • Fixed by: https://git.kernel.org/linus/a1b14d27ed0965838350f1377ff97c93ee383492 (v4.5-rc4)

  • Introduced by: https://git.kernel.org/linus/9bac3d6d548e5cc925570b263f35b70a00a00ffd (v4.1-rc1)

  • https://www.openwall.com/lists/oss-security/2016/02/14/1

EPSS

Процентиль: 25%
0.00084
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 10 лет назад

The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the backward-jump case, which allows local users to obtain sensitive information from kernel memory by creating a packet filter and then loading crafted BPF instructions.

redhat
почти 10 лет назад

The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the backward-jump case, which allows local users to obtain sensitive information from kernel memory by creating a packet filter and then loading crafted BPF instructions.

CVSS3: 5.5
nvd
почти 10 лет назад

The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the backward-jump case, which allows local users to obtain sensitive information from kernel memory by creating a packet filter and then loading crafted BPF instructions.

CVSS3: 5.5
github
больше 3 лет назад

The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the backward-jump case, which allows local users to obtain sensitive information from kernel memory by creating a packet filter and then loading crafted BPF instructions.

suse-cvrf
почти 10 лет назад

Security update for the Linux Kernel

EPSS

Процентиль: 25%
0.00084
Низкий