Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-7117

Опубликовано: 14 мар. 2016
Источник: redhat
CVSS3: 8.1
CVSS2: 7.6
EPSS Средний

Описание

Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandled during error processing.

A use-after-free vulnerability was found in the kernel's socket recvmmsg subsystem. This may allow remote attackers to corrupt memory and may allow execution of arbitrary code. This corruption takes place during the error handling routines within __sys_recvmmsg() function.

Отчет

This issue affects the Linux kernels as shipped with Red Hat Enterprise Linux 5, 6, 7, MRG-2 and realtime and may be addressed in a future update.

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1382268kernel: Use-after-free in the recvmmsg exit path

EPSS

Процентиль: 94%
0.12777
Средний

8.1 High

CVSS3

7.6 High

CVSS2

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandled during error processing.

CVSS3: 9.8
nvd
больше 8 лет назад

Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandled during error processing.

CVSS3: 9.8
debian
больше 8 лет назад

Use-after-free vulnerability in the __sys_recvmmsg function in net/soc ...

CVSS3: 9.8
github
около 3 лет назад

Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandled during error processing.

oracle-oval
больше 8 лет назад

ELSA-2016-3655: Unbreakable Enterprise kernel security update (IMPORTANT)

EPSS

Процентиль: 94%
0.12777
Средний

8.1 High

CVSS3

7.6 High

CVSS2