Описание
The IP stack in the Linux kernel before 4.6 allows remote attackers to cause a denial of service (stack consumption and panic) or possibly have unspecified other impact by triggering use of the GRO path for packets with tunnel stacking, as demonstrated by interleaved IPv4 headers and GRE headers, a related issue to CVE-2016-7039.
A flaw was found in the way the Linux kernel's networking subsystem handled offloaded packets with multiple layers of encapsulation in the GRO (Generic Receive Offload) code path. A remote attacker could use this flaw to trigger unbounded recursion in the kernel that could lead to stack corruption, resulting in a system crash.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | kernel | Not affected | ||
Red Hat Enterprise Linux 6 | kernel | Not affected | ||
Red Hat Enterprise Linux Extended Update Support 7.2 | kernel | Affected | ||
Red Hat Enterprise Linux 7 | kernel-rt | Fixed | RHSA-2016:2110 | 26.10.2016 |
Red Hat Enterprise Linux 7 | kernel | Fixed | RHSA-2016:2047 | 10.10.2016 |
Red Hat Enterprise Linux 7 | kernel-aarch64 | Fixed | RHSA-2017:0372 | 02.03.2017 |
Red Hat Enterprise Linux 7.1 Extended Update Support | kernel | Fixed | RHSA-2017:0004 | 03.01.2017 |
Red Hat Enterprise MRG 2 | kernel-rt | Fixed | RHSA-2016:2107 | 26.10.2016 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
7.1 High
CVSS2
Связанные уязвимости
The IP stack in the Linux kernel before 4.6 allows remote attackers to cause a denial of service (stack consumption and panic) or possibly have unspecified other impact by triggering use of the GRO path for packets with tunnel stacking, as demonstrated by interleaved IPv4 headers and GRE headers, a related issue to CVE-2016-7039.
The IP stack in the Linux kernel before 4.6 allows remote attackers to cause a denial of service (stack consumption and panic) or possibly have unspecified other impact by triggering use of the GRO path for packets with tunnel stacking, as demonstrated by interleaved IPv4 headers and GRE headers, a related issue to CVE-2016-7039.
The IP stack in the Linux kernel before 4.6 allows remote attackers to ...
The IP stack in the Linux kernel before 4.6 allows remote attackers to cause a denial of service (stack consumption and panic) or possibly have unspecified other impact by triggering use of the GRO path for packets with tunnel stacking, as demonstrated by interleaved IPv4 headers and GRE headers, a related issue to CVE-2016-7039.
Security update for Linux Kernel Live Patch 8 for SLE 12 SP1
EPSS
7.5 High
CVSS3
7.1 High
CVSS2