Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-3134

Опубликовано: 27 апр. 2016
Источник: debian

Описание

The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed4.5.1-1package
linuxno-dsawheezypackage

Примечания

  • https://code.google.com/p/google-security-research/issues/detail?id=758

  • https://patchwork.ozlabs.org/patch/595575/

  • http://marc.info/?l=netfilter-devel&m=145757134822741&w=2

  • https://www.openwall.com/lists/oss-security/2016/03/10/4

  • https://www.openwall.com/lists/oss-security/2016/03/10/7

  • Non-privileged user namespaces disabled by default, only vulnerable with sysctl kernel.unprivileged_userns_clone=1

Связанные уязвимости

CVSS3: 8.4
ubuntu
около 9 лет назад

The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.

CVSS3: 6.4
redhat
больше 9 лет назад

The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.

CVSS3: 8.4
nvd
около 9 лет назад

The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.

CVSS3: 8.4
github
около 3 лет назад

The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.

oracle-oval
больше 8 лет назад

ELSA-2016-3625: Unbreakable Enterprise kernel security and bugfix update (IMPORTANT)