Professional OVAL Repository
[Eng]
[Rus]
[Sign-In]
OVAL
Search
Categories
RedCheck
About
OVAL Definitions
OVAL Items
FSTEC Data Bank Information Security Threats
NKCKI
EOL (End Of Life)
Linux Security Advisories
Mozilla Foundation Security Advisory
IBM
VMware
Cisco
Check Point Software Technologies
Apache
Solaris
FreeBSD
Development
GitHub Enterprise
Google Chrome Security Advisories
Oracle Security Advisories
Adobe Security Advisories
OpenSSL Security Advisories
Microsoft
CVE
CWE
CPE
Latest Updates
OS ROSA
ALT Linux
Astra Linux
RED OS
DSA (Debian Security Advisory) Patсh Statistics
DSA (Debian Security Advisory) Patсh Feed
DSA (Debian Security Advisory) Vulnerability Feed
DLA (Debian Security Advisory) Patсh Statistics
DLA (Debian Security Advisory) Patсh Feed
DLA (Debian Security Advisory) Vulnerability Feed
ALT Linux (Security Bulletins) Patсh Statistics
ALT Linux (Security Bulletins) Patсh Feed
ALT Linux (Security Bulletins) Vulnerability Feed
RED OS (Security Bulletins) Patсh Statistics
RED OS (Security Bulletins) Patсh Feed
RED OS (Security Bulletins) Vulnerability Feed
USN (Ubuntu Security Notice) Patсh Statistics
USN (Ubuntu Security Notice) Patсh Feed
USN (Ubuntu Security Notice) Vulnerability Feed
RHSA (RedHat Security Advisory) Patсh Statistics
RHSA (RedHat Security Advisory) Patсh Feed
RHSA (RedHat Security Advisory) Vulnerability Feed
ELSA (Oracle Linux Security Advisory) Patсh Statistics
ELSA (Oracle Linux Security Advisory) Patсh Feed
ELSA (Oracle Linux Security Advisory) Vulnerability Feed
SUSE (SUSE Security Advisories) Patсh Statistics
SUSE (SUSE Security Advisories) Patсh Feed
SUSE (SUSE Security Advisories) Vulnerability Feed
openSUSE (openSUSE Security Advisories) Patсh Statistics
openSUSE (openSUSE Security Advisories) Patсh Feed
openSUSE (openSUSE Security Advisories) Vulnerability Feed
Amazon Linux AMI (Security Bulletins) Patсh Statistics
Amazon Linux AMI (Security Bulletins) Patсh Feed
Amazon Linux AMI (Security Bulletins) Vulnerability Feed
Mageia Linux (Security Bulletins) Patсh Statistics
Mageia Linux (Security Bulletins) Patсh Feed
Mageia Linux (Security Bulletins) Vulnerability Feed
OS ROSA SX COBALT 1.0
OS ROSA DX COBALT 1.0
ROSA 7.3 (Security Advisories) Patсh Statistics
ROSA 7.3 (Security Advisories) Patсh Feed
ROSA 7.3 (Security Advisories) Vulnerability Feed
ALT Linux SPT 6.0
ALT Linux SPT 7.0
ALT 8 SP
ALT 9
Astra Linux SE 1.5
Astra Linux SE 1.6
Astra Linux SE 1.7
Astra Linux SE 1.8
RED OS Murom 7.1
RED OS Murom 7.2
IBM DB2
VMware Vulnerabilities Advisory (VMSA)
VMware vCenter Patch Advisories
VMware ESXi Patch Advisories
VMware NSX Patches
VMware NSX Vulnerabilities
VMware Photon OS 1.0 Patches
VMware Photon OS 1.0 Vulnerabilities
VMware Photon OS 2.0 Patches
VMware Photon OS 2.0 Vulnerabilities
Cisco ASA
Cisco IOS/NX-OS Advisory
Cisco NX-OS Vulnerabilities
Check Point Gaia
Apache Tomcat Advisories
Apache Tomcat Server
Apache HTTP Server
Python
Node.js
RubyGems
Qt
Microsoft Security Bulletin
Microsoft Knowledge Base Article
Microsoft SharePoint
Microsoft SharePoint Foundation 2013
Microsoft SharePoint Server 2013
Microsoft SharePoint Server 2016
About OVALdb
User manual
Pricing
Contact us
OVAL Definitions
>
OVAL Definition Details
Id
oval:com.altx-soft.nix:def:30298
[Rus]
Version
5
Class
patch
ALTXid
178798
Language
English
Severity
High
Title
openSUSE-SU-2016:2144-1 -- Security update for the Linux Kernel
Description
The openSUSE 13.2 kernel was updated to fix various bugs and security issues
Family
unix
Platform
openSUSE 13.2
Product
xen
Reference
VENDOR: openSUSE-SU-2016:2144-1
VENDOR: openSUSE-SU-2016:2144-1
Id:
openSUSE-SU-2016:2144-1
Reference:
https://lists.opensuse.org/opensuse-updates/2016-08/msg00099.html
CVE: CVE-2012-6701
CVE: CVE-2012-6701
Id:
CVE-2012-6701
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6701
Comment
: Integer overflow in fs/aio.c in the Linux kernel before 3.4.1 allows local users to cause a denial of service or possibly have unspecified other impact via a large AIO iovec.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
190 (Integer Overflow or Wraparound)
References:
https://github.com/torvalds/linux/commit/a70b52ec1aaeaf60f4739edb1b422827cb6f3893 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a70b52ec1aaeaf60f4739edb1b422827cb6f3893 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1314288 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.4.1 (CONFIRM)
[oss-security] 20160302 Re: CVE Request: Linux: aio write triggers integer overflow in some network protocols (MLIST)
RHSA-2018:1854 (REDHAT)
CVE: CVE-2013-7446
CVE: CVE-2013-7446
Id:
CVE-2013-7446
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7446
Comment
: Use-after-free vulnerability in net/unix/af_unix.c in the Linux kernel before 4.3.3 allows local users to bypass intended AF_UNIX socket permissions or cause a denial of service (panic) via crafted epoll_ctl calls.
CVSSv2 Score:
5.4
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
PARTIAL
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:P/A:C
CVSSv3 Score:
5.3
Attack vector:
LOCAL
Attack complexity:
HIGH
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
LOW
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H
CWE:
CWE-Other ()
References:
https://forums.grsecurity.net/viewtopic.php?f=3&t=4150 (MISC)
https://github.com/torvalds/linux/commit/7d267278a9ece963d77eefec61630223fce08c6c (CONFIRM)
[netdev] 20150304 [PATCH net] af_unix: don't poll dead peers (MLIST)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=7d267278a9ece963d77eefec61630223fce08c6c (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.3.3 (CONFIRM)
[oss-security] 20151118 Re: CVE request - Linux kernel - Unix sockets use after free - peer_wait_queue prematurely freed (MLIST)
[linux-kernel] 20140515 eventpoll __list_del_entry corruption (was: perf: use after free in perf_remove_from_context) (MLIST)
[linux-kernel] 20150913 List corruption on epoll_ctl(EPOLL_CTL_DEL) an AF_UNIX socket (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=1282688 (CONFIRM)
[linux-kernel] 20131014 Re: epoll oops. (MLIST)
SUSE-SU-2016:1995 (SUSE)
SUSE-SU-2016:2000 (SUSE)
SUSE-SU-2016:2002 (SUSE)
SUSE-SU-2016:1961 (SUSE)
SUSE-SU-2016:2014 (SUSE)
SUSE-SU-2016:2006 (SUSE)
SUSE-SU-2016:2074 (SUSE)
SUSE-SU-2016:2007 (SUSE)
SUSE-SU-2016:2010 (SUSE)
openSUSE-SU-2016:1641 (SUSE)
SUSE-SU-2016:2001 (SUSE)
SUSE-SU-2016:1994 (SUSE)
SUSE-SU-2016:2003 (SUSE)
77638 (BID)
SUSE-SU-2016:2011 (SUSE)
SUSE-SU-2016:2005 (SUSE)
SUSE-SU-2016:2009 (SUSE)
SUSE-SU-2016:0757 (SUSE)
SUSE-SU-2016:0755 (SUSE)
SUSE-SU-2016:0746 (SUSE)
SUSE-SU-2016:0753 (SUSE)
SUSE-SU-2016:0750 (SUSE)
SUSE-SU-2016:0756 (SUSE)
SUSE-SU-2016:0754 (SUSE)
SUSE-SU-2016:0747 (SUSE)
SUSE-SU-2016:0745 (SUSE)
SUSE-SU-2016:0752 (SUSE)
SUSE-SU-2016:0911 (SUSE)
SUSE-SU-2016:1102 (SUSE)
SUSE-SU-2016:0749 (SUSE)
SUSE-SU-2016:0751 (SUSE)
USN-2889-1 (UBUNTU)
USN-2890-1 (UBUNTU)
USN-2889-2 (UBUNTU)
USN-2890-2 (UBUNTU)
USN-2887-1 (UBUNTU)
USN-2890-3 (UBUNTU)
USN-2887-2 (UBUNTU)
USN-2888-1 (UBUNTU)
USN-2886-1 (UBUNTU)
DSA-3426 (DEBIAN)
1034557 (SECTRACK)
https://groups.google.com/forum/#%21topic/syzkaller/3twDUI4Cpm8 ()
CVE: CVE-2014-9904
CVE: CVE-2014-9904
Id:
CVE-2014-9904
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9904
Comment
: The snd_compress_check_input function in sound/core/compress_offload.c in the ALSA subsystem in the Linux kernel before 3.17 does not properly check for an integer overflow, which allows local users to cause a denial of service (insufficient memory allocation) or possibly have unspecified other impact via a crafted SNDRV_COMPRESS_SET_PARAMS ioctl call.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
CWE-Other ()
References:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6217e5ede23285ddfee10d2e4ba0cc2d4c046205 (CONFIRM)
https://github.com/torvalds/linux/commit/6217e5ede23285ddfee10d2e4ba0cc2d4c046205 (CONFIRM)
DSA-3616 (DEBIAN)
SUSE-SU-2016:1937 (SUSE)
openSUSE-SU-2016:2184 (SUSE)
SUSE-SU-2016:2105 (SUSE)
91510 (BID)
1036189 (SECTRACK)
CVE: CVE-2015-3288
CVE: CVE-2015-3288
Id:
CVE-2015-3288
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3288
Comment
: mm/memory.c in the Linux kernel before 4.1.4 mishandles anonymous pages, which allows local users to gain privileges or cause a denial of service (page tainting) via a crafted application that triggers writing to page zero.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
20 (Improper Input Validation)
References:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6b7339f4c31ad69c8e9c0b2859276e22cf72176d (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.1.4 (CONFIRM)
https://security-tracker.debian.org/tracker/CVE-2015-3288 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1333830 (CONFIRM)
https://github.com/torvalds/linux/commit/6b7339f4c31ad69c8e9c0b2859276e22cf72176d (CONFIRM)
93591 (BID)
https://source.android.com/security/bulletin/2017-01-01.html (CONFIRM)
CVE: CVE-2015-6526
CVE: CVE-2015-6526
Id:
CVE-2015-6526
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6526
Comment
: The perf_callchain_user_64 function in arch/powerpc/perf/callchain.c in the Linux kernel before 4.0.2 on ppc64 platforms allows local users to cause a denial of service (infinite loop) via a deep 64-bit userspace backtrace.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
399 (Resource Management Errors)
References:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=9a5cbce421a283e6aea3c4007f141735bf9da8c3 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.0.2 (CONFIRM)
[oss-security] 20150818 CVE request - Linux kernel - perf on ppp64 - unbounded checks in perf_callchain_user_64 denial of service. (MLIST)
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html (CONFIRM)
76401 (BID)
1033728 (SECTRACK)
USN-2759-1 (UBUNTU)
USN-2760-1 (UBUNTU)
https://bugzilla.redhat.com/show_bug.cgi?id=1218454 (CONFIRM)
https://github.com/torvalds/linux/commit/9a5cbce421a283e6aea3c4007f141735bf9da8c3 (CONFIRM)
CVE: CVE-2015-7566
CVE: CVE-2015-7566
Id:
CVE-2015-7566
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7566
Comment
: The clie_5_attach function in drivers/usb/serial/visor.c in the Linux kernel through 4.4.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a bulk-out endpoint.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
4.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
CWE-Other ()
References:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cb3232138e37129e88240a98a1d2aba2187ff57c (CONFIRM)
FEDORA-2016-5d43766e33 (FEDORA)
FEDORA-2016-26e19f042a (FEDORA)
FEDORA-2016-b59fd603be (FEDORA)
SUSE-SU-2016:1672 (SUSE)
SUSE-SU-2016:1707 (SUSE)
SUSE-SU-2016:1764 (SUSE)
SUSE-SU-2016:2074 (SUSE)
DSA-3448 (DEBIAN)
DSA-3503 (DEBIAN)
20160309 OS-S 2016-09 Linux visor clie_5_attach Nullpointer Dereference CVE-2015-7566 (BUGTRAQ)
82975 (BID)
USN-2929-1 (UBUNTU)
USN-2929-2 (UBUNTU)
USN-2930-1 (UBUNTU)
USN-2930-2 (UBUNTU)
USN-2930-3 (UBUNTU)
USN-2932-1 (UBUNTU)
USN-2948-1 (UBUNTU)
USN-2948-2 (UBUNTU)
USN-2967-1 (UBUNTU)
USN-2967-2 (UBUNTU)
https://bugzilla.redhat.com/show_bug.cgi?id=1283371 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1296466 (CONFIRM)
https://github.com/torvalds/linux/commit/cb3232138e37129e88240a98a1d2aba2187ff57c (CONFIRM)
https://security-tracker.debian.org/tracker/CVE-2015-7566 (CONFIRM)
39540 (EXPLOIT-DB)
CVE: CVE-2015-8709
CVE: CVE-2015-8709
Id:
CVE-2015-8709
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8709
Comment
: kernel/ptrace.c in the Linux kernel through 4.4.1 mishandles uid and gid mappings, which allows local users to gain privileges by establishing a user namespace, waiting for a root process to enter that namespace with an unsafe uid or gid, and then using the ptrace system call. NOTE: the vendor states "there is no kernel bug here.
CVSSv2 Score:
6.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7
Attack vector:
LOCAL
Attack complexity:
HIGH
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
264 (Permissions, Privileges, and Access Controls)
References:
[oss-security] 20151231 Re: CVE Request: Linux kernel: privilege escalation in user namespaces (MLIST)
[linux-kernel] 20160106 Re: [PATCH] ptrace: being capable wrt a process requires mapped uids/gids (MLIST)
[linux-kernel] 20160106 Re: [PATCH] ptrace: being capable wrt a process requires mapped uids/gids (MLIST)
[oss-security] 20151217 CVE Request: Linux kernel: privilege escalation in user namespaces (MLIST)
[linux-kernel] 20151226 [PATCH] ptrace: being capable wrt a process requires mapped uids/gids (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=1295287 (CONFIRM)
SUSE-SU-2016:1764 (SUSE)
openSUSE-SU-2016:1008 (SUSE)
SUSE-SU-2016:1039 (SUSE)
SUSE-SU-2016:1035 (SUSE)
SUSE-SU-2016:1040 (SUSE)
SUSE-SU-2016:1033 (SUSE)
SUSE-SU-2016:1034 (SUSE)
SUSE-SU-2016:1045 (SUSE)
SUSE-SU-2016:1041 (SUSE)
SUSE-SU-2016:1038 (SUSE)
SUSE-SU-2016:1037 (SUSE)
SUSE-SU-2016:1019 (SUSE)
SUSE-SU-2016:1046 (SUSE)
SUSE-SU-2016:1031 (SUSE)
SUSE-SU-2016:1032 (SUSE)
FEDORA-2016-5d43766e33 (FEDORA)
1034899 (SECTRACK)
79899 (BID)
DSA-3434 (DEBIAN)
CVE: CVE-2015-8785
CVE: CVE-2015-8785
Id:
CVE-2015-8785
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8785
Comment
: The fuse_fill_write_pages function in fs/fuse/file.c in the Linux kernel before 4.4 allows local users to cause a denial of service (infinite loop) via a writev system call that triggers a zero length for the first segment of an iov.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
6.2
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
835 (Loop with Unreachable Exit Condition ('Infinite Loop'))
References:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=3ca8138f014a913f98e6ef40e939868e1e9ea876 (CONFIRM)
[oss-security] 20160124 CVE Request: Linux: fuse: possible denial of service in fuse_fill_write_pages() (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=1290642 (CONFIRM)
https://github.com/torvalds/linux/commit/3ca8138f014a913f98e6ef40e939868e1e9ea876 (CONFIRM)
SUSE-SU-2016:1764 (SUSE)
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html (CONFIRM)
http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html (CONFIRM)
SUSE-SU-2016:2074 (SUSE)
81688 (BID)
DSA-3503 (DEBIAN)
openSUSE-SU-2016:1008 (SUSE)
SUSE-SU-2016:0911 (SUSE)
SUSE-SU-2016:1102 (SUSE)
USN-2886-1 (UBUNTU)
CVE: CVE-2015-8812
CVE: CVE-2015-8812
Id:
CVE-2015-8812
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8812
Comment
: drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted packets.
CVSSv2 Score:
10
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
9.8
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE:
CWE-Other ()
References:
https://bugzilla.redhat.com/show_bug.cgi?id=1303532 (CONFIRM)
[oss-security] 20160211 Linux kernel: Flaw in CXGB3 driver. (MLIST)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=67f1aee6f45059fd6b0f5b0ecb2c97ad0451f6b3 (CONFIRM)
https://github.com/torvalds/linux/commit/67f1aee6f45059fd6b0f5b0ecb2c97ad0451f6b3 (CONFIRM)
SUSE-SU-2016:1764 (SUSE)
SUSE-SU-2016:2074 (SUSE)
83218 (BID)
DSA-3503 (DEBIAN)
USN-2967-1 (UBUNTU)
USN-2967-2 (UBUNTU)
openSUSE-SU-2016:1008 (SUSE)
SUSE-SU-2016:1039 (SUSE)
SUSE-SU-2016:1035 (SUSE)
SUSE-SU-2016:1033 (SUSE)
USN-2946-2 (UBUNTU)
SUSE-SU-2016:1045 (SUSE)
SUSE-SU-2016:1041 (SUSE)
SUSE-SU-2016:1037 (SUSE)
USN-2947-3 (UBUNTU)
USN-2948-2 (UBUNTU)
SUSE-SU-2016:1046 (SUSE)
USN-2947-1 (UBUNTU)
SUSE-SU-2016:1031 (SUSE)
USN-2949-1 (UBUNTU)
SUSE-SU-2016:1040 (SUSE)
SUSE-SU-2016:1034 (SUSE)
USN-2947-2 (UBUNTU)
USN-2946-1 (UBUNTU)
SUSE-SU-2016:1038 (SUSE)
SUSE-SU-2016:1019 (SUSE)
SUSE-SU-2016:0911 (SUSE)
SUSE-SU-2016:1032 (SUSE)
SUSE-SU-2016:1102 (SUSE)
USN-2948-1 (UBUNTU)
RHSA-2016:2584 (REDHAT)
RHSA-2016:2574 (REDHAT)
CVE: CVE-2015-8816
CVE: CVE-2015-8816
Id:
CVE-2015-8816
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8816
Comment
: The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB hub device.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
6.8
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE:
CWE-Other ()
References:
https://bugzilla.redhat.com/show_bug.cgi?id=1311589 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e50293ef9775c5f1cf3fcc093037dd6a8c5684ea (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.3.5 (CONFIRM)
[oss-security] 20160223 CVE Request: Linux kernel USB hub invalid memory access in hub_activate() (MLIST)
https://github.com/torvalds/linux/commit/e50293ef9775c5f1cf3fcc093037dd6a8c5684ea (CONFIRM)
http://source.android.com/security/bulletin/2016-07-01.html (CONFIRM)
SUSE-SU-2016:1672 (SUSE)
SUSE-SU-2016:1690 (SUSE)
SUSE-SU-2016:1707 (SUSE)
SUSE-SU-2016:1764 (SUSE)
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html (CONFIRM)
http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html (CONFIRM)
SUSE-SU-2016:1995 (SUSE)
SUSE-SU-2016:2002 (SUSE)
SUSE-SU-2016:1961 (SUSE)
SUSE-SU-2016:2014 (SUSE)
SUSE-SU-2016:2006 (SUSE)
SUSE-SU-2016:2074 (SUSE)
SUSE-SU-2016:2007 (SUSE)
SUSE-SU-2016:2010 (SUSE)
83363 (BID)
SUSE-SU-2016:2001 (SUSE)
SUSE-SU-2016:1994 (SUSE)
SUSE-SU-2016:2005 (SUSE)
SUSE-SU-2016:2009 (SUSE)
DSA-3503 (DEBIAN)
SUSE-SU-2016:1019 (SUSE)
CVE: CVE-2015-8830
CVE: CVE-2015-8830
Id:
CVE-2015-8830
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8830
Comment
: Integer overflow in the aio_setup_single_vector function in fs/aio.c in the Linux kernel 4.0 allows local users to cause a denial of service or possibly have unspecified other impact via a large AIO iovec. NOTE: this vulnerability exists because of a CVE-2012-6701 regression.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
CWE-Other ()
References:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=4c185ce06dca14f5cea192f5a2c981ef50663f2b (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c4f4b82694fe48b02f7a881a1797131a6dad1364 (CONFIRM)
DSA-3503 (DEBIAN)
[oss-security] 20160302 Re: CVE Request: Linux: aio write triggers integer overflow in some network protocols (MLIST)
USN-2968-1 (UBUNTU)
USN-2968-2 (UBUNTU)
USN-2969-1 (UBUNTU)
USN-2970-1 (UBUNTU)
RHSA-2018:1854 (REDHAT)
RHSA-2018:3083 (REDHAT)
RHSA-2018:3096 (REDHAT)
https://bugzilla.redhat.com/show_bug.cgi?id=1314275 (CONFIRM)
https://github.com/torvalds/linux/commit/4c185ce06dca14f5cea192f5a2c981ef50663f2b (CONFIRM)
https://github.com/torvalds/linux/commit/c4f4b82694fe48b02f7a881a1797131a6dad1364 (CONFIRM)
CVE: CVE-2016-0758
CVE: CVE-2016-0758
Id:
CVE-2016-0758
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0758
Comment
: Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
CWE-Other ()
References:
https://bugzilla.redhat.com/show_bug.cgi?id=1300257 (CONFIRM)
[oss-security] 20160513 CVE-2016-0758 - Linux kernel - Flaw in ASN.1 DER decoder for x509 certificate DER files. (MLIST)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=23c8a812dc3c621009e4f0e5342aa4e2ede1ceaa (CONFIRM)
https://github.com/torvalds/linux/commit/23c8a812dc3c621009e4f0e5342aa4e2ede1ceaa (CONFIRM)
RHSA-2016:1033 (REDHAT)
SUSE-SU-2016:1672 (SUSE)
RHSA-2016:1051 (REDHAT)
SUSE-SU-2016:1690 (SUSE)
HPSBHF3548 (HP)
RHSA-2016:1055 (REDHAT)
USN-2979-4 (UBUNTU)
SUSE-SU-2016:1937 (SUSE)
http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html (CONFIRM)
http://source.android.com/security/bulletin/2016-10-01.html (CONFIRM)
SUSE-SU-2016:1995 (SUSE)
SUSE-SU-2016:2000 (SUSE)
SUSE-SU-2016:2002 (SUSE)
SUSE-SU-2016:1961 (SUSE)
SUSE-SU-2016:2014 (SUSE)
SUSE-SU-2016:2006 (SUSE)
SUSE-SU-2016:2007 (SUSE)
SUSE-SU-2016:1985 (SUSE)
SUSE-SU-2016:2010 (SUSE)
openSUSE-SU-2016:1641 (SUSE)
openSUSE-SU-2016:2184 (SUSE)
SUSE-SU-2016:2001 (SUSE)
SUSE-SU-2016:1994 (SUSE)
SUSE-SU-2016:2003 (SUSE)
SUSE-SU-2016:2011 (SUSE)
90626 (BID)
SUSE-SU-2016:2005 (SUSE)
SUSE-SU-2016:2105 (SUSE)
SUSE-SU-2016:2009 (SUSE)
CVE: CVE-2016-1583
CVE: CVE-2016-1583
Id:
CVE-2016-1583
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1583
Comment
: The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted mmap calls for /proc pathnames, leading to recursive pagefault handling.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)
References:
https://github.com/torvalds/linux/commit/2f36db71009304b3f0b95afacd8eba1f9f046b87 (CONFIRM)
https://github.com/torvalds/linux/commit/f5364c150aa645b3d7daa21b5c0b9feaa1c9cd6d (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2f36db71009304b3f0b95afacd8eba1f9f046b87 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1344721 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f5364c150aa645b3d7daa21b5c0b9feaa1c9cd6d (CONFIRM)
https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.6.3 (CONFIRM)
[oss-security] 20160622 Re: [vs-plain] Linux kernel stack overflow via ecryptfs and /proc/$pid/environ (MLIST)
https://bugs.chromium.org/p/project-zero/issues/detail?id=836 (MISC)
[oss-security] 20160610 [vs-plain] Linux kernel stack overflow via ecryptfs and /proc/$pid/environ (MLIST)
USN-2997-1 (UBUNTU)
USN-2996-1 (UBUNTU)
USN-3002-1 (UBUNTU)
USN-3001-1 (UBUNTU)
USN-3004-1 (UBUNTU)
USN-3000-1 (UBUNTU)
USN-2998-1 (UBUNTU)
USN-3003-1 (UBUNTU)
39992 (EXPLOIT-DB)
http://packetstormsecurity.com/files/137560/Linux-ecryptfs-Stack-Overflow.html (MISC)
USN-3005-1 (UBUNTU)
USN-3006-1 (UBUNTU)
USN-2999-1 (UBUNTU)
SUSE-SU-2016:1596 (SUSE)
USN-3007-1 (UBUNTU)
SUSE-SU-2016:1672 (SUSE)
SUSE-SU-2016:1696 (SUSE)
USN-3008-1 (UBUNTU)
SUSE-SU-2016:1937 (SUSE)
SUSE-SU-2016:1995 (SUSE)
SUSE-SU-2016:2000 (SUSE)
SUSE-SU-2016:2002 (SUSE)
DSA-3607 (DEBIAN)
SUSE-SU-2016:1961 (SUSE)
91157 (BID)
SUSE-SU-2016:2014 (SUSE)
SUSE-SU-2016:2006 (SUSE)
SUSE-SU-2016:2007 (SUSE)
SUSE-SU-2016:1985 (SUSE)
SUSE-SU-2016:2010 (SUSE)
openSUSE-SU-2016:1641 (SUSE)
openSUSE-SU-2016:2184 (SUSE)
SUSE-SU-2016:1994 (SUSE)
SUSE-SU-2016:2005 (SUSE)
SUSE-SU-2016:2105 (SUSE)
SUSE-SU-2016:2009 (SUSE)
1036763 (SECTRACK)
RHSA-2017:2760 (REDHAT)
RHSA-2016:2766 (REDHAT)
RHSA-2016:2124 (REDHAT)
https://github.com/torvalds/linux/commit/f0fe970df3838c202ef6c07a4c2b36838ef0a88b (MISC)
CVE: CVE-2016-2053
CVE: CVE-2016-2053
Id:
CVE-2016-2053
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2053
Comment
: The asn1_ber_decoder function in lib/asn1_decoder.c in the Linux kernel before 4.3 allows attackers to cause a denial of service (panic) via an ASN.1 BER file that lacks a public key, leading to mishandling by the public_key_verify_signature function in crypto/asymmetric_keys/public_key.c.
CVSSv2 Score:
4.7
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:N/A:C
CVSSv3 Score:
4.7
Attack vector:
LOCAL
Attack complexity:
HIGH
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
310 (Cryptographic Issues)
References:
[oss-security] 20160125 Re: Linux kernel : Denial of service with specially crafted key file. (MLIST)
https://github.com/torvalds/linux/commit/0d62e9dd6da45bbf0f33a8617afc5fe774c8f45f (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1300237 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0d62e9dd6da45bbf0f33a8617afc5fe774c8f45f (CONFIRM)
SUSE-SU-2016:1672 (SUSE)
SUSE-SU-2016:1690 (SUSE)
SUSE-SU-2016:1937 (SUSE)
SUSE-SU-2016:1995 (SUSE)
SUSE-SU-2016:2000 (SUSE)
SUSE-SU-2016:2002 (SUSE)
SUSE-SU-2016:1961 (SUSE)
SUSE-SU-2016:2014 (SUSE)
SUSE-SU-2016:2006 (SUSE)
SUSE-SU-2016:2007 (SUSE)
SUSE-SU-2016:1985 (SUSE)
SUSE-SU-2016:2010 (SUSE)
openSUSE-SU-2016:1641 (SUSE)
openSUSE-SU-2016:2184 (SUSE)
SUSE-SU-2016:2001 (SUSE)
SUSE-SU-2016:1994 (SUSE)
SUSE-SU-2016:2003 (SUSE)
SUSE-SU-2016:2011 (SUSE)
SUSE-SU-2016:2005 (SUSE)
SUSE-SU-2016:2105 (SUSE)
SUSE-SU-2016:2009 (SUSE)
1036763 (SECTRACK)
RHSA-2016:2584 (REDHAT)
RHSA-2016:2574 (REDHAT)
CVE: CVE-2016-2184
CVE: CVE-2016-2184
Id:
CVE-2016-2184
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2184
Comment
: The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference or double free, and system crash) via a crafted endpoints value in a USB device descriptor.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
4.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
CWE-Other ()
References:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0f886ca12765d20124bd06291c82951fd49a33be (CONFIRM)
https://github.com/torvalds/linux/commit/0f886ca12765d20124bd06291c82951fd49a33be (CONFIRM)
20160310 oss-2016-17: Local RedHat Enterprise Linux DoS - RHEL 7.1 Kernel crashes (multiple free) on invalid USB device descriptors (snd-usb-audio driver) (BUGTRAQ)
https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.1 (CONFIRM)
20160310 oss-2016-16: Local RedHat Enterprise Linux DoS - RHEL 7.1 Kernel crashes on invalid USB device descriptors (snd-usb-audio driver) (BUGTRAQ)
20160314 Re: oss-2016-17: Local RedHat Enterprise Linux DoS - RHEL 7.1 Kernel crashes (multiple free) on invalid USB device descriptors (snd-usb-audio driver) (BUGTRAQ)
https://bugzilla.redhat.com/show_bug.cgi?id=1317012 (CONFIRM)
USN-2997-1 (UBUNTU)
USN-2996-1 (UBUNTU)
SUSE-SU-2016:1672 (SUSE)
SUSE-SU-2016:1690 (SUSE)
SUSE-SU-2016:1707 (SUSE)
SUSE-SU-2016:1764 (SUSE)
DSA-3607 (DEBIAN)
SUSE-SU-2016:2074 (SUSE)
https://source.android.com/security/bulletin/2016-11-01.html (CONFIRM)
84340 (BID)
openSUSE-SU-2016:1008 (SUSE)
USN-2969-1 (UBUNTU)
USN-2971-1 (UBUNTU)
USN-2971-3 (UBUNTU)
USN-2968-1 (UBUNTU)
USN-2971-2 (UBUNTU)
USN-2970-1 (UBUNTU)
USN-2968-2 (UBUNTU)
SUSE-SU-2016:1019 (SUSE)
39555 (EXPLOIT-DB)
CVE: CVE-2016-2185
CVE: CVE-2016-2185
Id:
CVE-2016-2185
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2185
Comment
: The ati_remote2_probe function in drivers/input/misc/ati_remote2.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
4.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
CWE-Other ()
References:
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.1 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1283362 (CONFIRM)
https://github.com/torvalds/linux/commit/950336ba3e4a1ffd2ca60d29f6ef386dd2c7351d (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=950336ba3e4a1ffd2ca60d29f6ef386dd2c7351d (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1283363 (CONFIRM)
20160315 Re: oss-2016-18: Multiple Local RedHat Enterprise Linux DoS - RHEL 7.1 Kernel crashes on invalid USB device descriptors (ati_remote2 driver) (BUGTRAQ)
https://bugzilla.redhat.com/show_bug.cgi?id=1317014 (CONFIRM)
20160310 oss-2016-18: Multiple Local RedHat Enterprise Linux DoS - RHEL 7.1 Kernel crashes on invalid USB device descriptors (ati_remote2 driver) (BUGTRAQ)
USN-2997-1 (UBUNTU)
USN-2996-1 (UBUNTU)
SUSE-SU-2016:1672 (SUSE)
SUSE-SU-2016:1696 (SUSE)
SUSE-SU-2016:1690 (SUSE)
SUSE-SU-2016:1707 (SUSE)
SUSE-SU-2016:1764 (SUSE)
DSA-3607 (DEBIAN)
84341 (BID)
SUSE-SU-2016:2074 (SUSE)
USN-2969-1 (UBUNTU)
USN-2971-1 (UBUNTU)
USN-2971-3 (UBUNTU)
openSUSE-SU-2016:1382 (SUSE)
USN-2968-1 (UBUNTU)
USN-2971-2 (UBUNTU)
USN-2970-1 (UBUNTU)
USN-2968-2 (UBUNTU)
CVE: CVE-2016-2186
CVE: CVE-2016-2186
Id:
CVE-2016-2186
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2186
Comment
: The powermate_probe function in drivers/input/misc/powermate.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
4.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
CWE-Other ()
References:
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.1 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=9c6ba456711687b794dcf285856fc14e2c76074f (CONFIRM)
20160310 oss-2016-13: Local RedHat Enterprise Linux DoS - RHEL 7.1 Kernel crashes on invalid USB device descriptors (powermate driver) (BUGTRAQ)
https://bugzilla.redhat.com/show_bug.cgi?id=1317015 (CONFIRM)
20160315 Re: oss-2016-13: Local RedHat Enterprise Linux DoS - RHEL 7.1 Kernel crashes on invalid USB device descriptors (powermate driver) (BUGTRAQ)
https://github.com/torvalds/linux/commit/9c6ba456711687b794dcf285856fc14e2c76074f (CONFIRM)
USN-2997-1 (UBUNTU)
USN-2996-1 (UBUNTU)
SUSE-SU-2016:1672 (SUSE)
SUSE-SU-2016:1696 (SUSE)
SUSE-SU-2016:1690 (SUSE)
SUSE-SU-2016:1707 (SUSE)
SUSE-SU-2016:1764 (SUSE)
84337 (BID)
DSA-3607 (DEBIAN)
SUSE-SU-2016:2074 (SUSE)
openSUSE-SU-2016:1382 (SUSE)
USN-2968-1 (UBUNTU)
USN-2969-1 (UBUNTU)
USN-2971-1 (UBUNTU)
USN-2971-2 (UBUNTU)
USN-2970-1 (UBUNTU)
USN-2971-3 (UBUNTU)
USN-2968-2 (UBUNTU)
CVE: CVE-2016-2187
CVE: CVE-2016-2187
Id:
CVE-2016-2187
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2187
Comment
: The gtco_probe function in drivers/input/tablet/gtco.c in the Linux kernel through 4.5.2 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
4.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
CWE-Other ()
References:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=162f98dea487206d9ab79fc12ed64700667a894d (CONFIRM)
https://github.com/torvalds/linux/commit/162f98dea487206d9ab79fc12ed64700667a894d (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1317017 (CONFIRM)
USN-2997-1 (UBUNTU)
USN-2996-1 (UBUNTU)
USN-3000-1 (UBUNTU)
USN-2998-1 (UBUNTU)
USN-3002-1 (UBUNTU)
USN-3003-1 (UBUNTU)
USN-3001-1 (UBUNTU)
USN-3004-1 (UBUNTU)
USN-2989-1 (UBUNTU)
USN-3005-1 (UBUNTU)
USN-3007-1 (UBUNTU)
SUSE-SU-2016:1672 (SUSE)
USN-3006-1 (UBUNTU)
DSA-3607 (DEBIAN)
85425 (BID)
SUSE-SU-2016:1985 (SUSE)
CVE: CVE-2016-2188
CVE: CVE-2016-2188
Id:
CVE-2016-2188
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2188
Comment
: The iowarrior_probe function in drivers/usb/misc/iowarrior.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
4.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
CWE-Other ()
References:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=4ec0ef3a82125efc36173062a50624550a900ae0 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.1 (CONFIRM)
20160310 oss-2016-15: Local RedHat Enterprise Linux DoS - RHEL 7.1 Kernel crashes on invalid USB device descriptors (iowarrior driver) (BUGTRAQ)
https://bugzilla.redhat.com/show_bug.cgi?id=1317018 (CONFIRM)
20160315 Re: oss-2016-15: Local RedHat Enterprise Linux DoS - RHEL 7.1 Kernel crashes on invalid USB device descriptors (iowarrior driver) (BUGTRAQ)
https://github.com/torvalds/linux/commit/4ec0ef3a82125efc36173062a50624550a900ae0 (CONFIRM)
USN-2997-1 (UBUNTU)
USN-2996-1 (UBUNTU)
SUSE-SU-2016:1672 (SUSE)
SUSE-SU-2016:1696 (SUSE)
SUSE-SU-2016:1690 (SUSE)
SUSE-SU-2016:1707 (SUSE)
SUSE-SU-2016:1764 (SUSE)
SUSE-SU-2016:2074 (SUSE)
openSUSE-SU-2016:1382 (SUSE)
USN-2968-1 (UBUNTU)
USN-2969-1 (UBUNTU)
USN-2971-1 (UBUNTU)
USN-2971-2 (UBUNTU)
USN-2970-1 (UBUNTU)
USN-2971-3 (UBUNTU)
USN-2968-2 (UBUNTU)
39556 (EXPLOIT-DB)
CVE: CVE-2016-2384
CVE: CVE-2016-2384
Id:
CVE-2016-2384
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2384
Comment
: Double free vulnerability in the snd_usbmidi_create function in sound/usb/midi.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (panic) or possibly have unspecified other impact via vectors involving an invalid USB descriptor.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
4.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
CWE-Other ()
References:
[oss-security] 20160214 CVE Request: Linux: ALSA: usb-audio: double-free triggered by invalid USB descriptor (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=1308444 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=07d86ca93db7e5cdf4743564d98292042ec21af7 (CONFIRM)
https://github.com/torvalds/linux/commit/07d86ca93db7e5cdf4743564d98292042ec21af7 (CONFIRM)
SUSE-SU-2016:1764 (SUSE)
SUSE-SU-2016:2074 (SUSE)
83256 (BID)
DSA-3503 (DEBIAN)
openSUSE-SU-2016:1008 (SUSE)
SUSE-SU-2016:1039 (SUSE)
SUSE-SU-2016:1035 (SUSE)
SUSE-SU-2016:1033 (SUSE)
USN-2930-1 (UBUNTU)
SUSE-SU-2016:1045 (SUSE)
USN-2929-1 (UBUNTU)
SUSE-SU-2016:1041 (SUSE)
SUSE-SU-2016:1037 (SUSE)
USN-2932-1 (UBUNTU)
USN-2928-1 (UBUNTU)
SUSE-SU-2016:1046 (SUSE)
USN-2930-2 (UBUNTU)
USN-2929-2 (UBUNTU)
SUSE-SU-2016:1031 (SUSE)
SUSE-SU-2016:1040 (SUSE)
SUSE-SU-2016:1034 (SUSE)
USN-2931-1 (UBUNTU)
SUSE-SU-2016:1038 (SUSE)
SUSE-SU-2016:1019 (SUSE)
USN-2930-3 (UBUNTU)
SUSE-SU-2016:0911 (SUSE)
SUSE-SU-2016:1032 (SUSE)
SUSE-SU-2016:1102 (SUSE)
USN-2928-2 (UBUNTU)
1035072 (SECTRACK)
https://github.com/xairy/kernel-exploits/tree/master/CVE-2016-2384 (MISC)
RHSA-2017:0817 (REDHAT)
RHSA-2016:2584 (REDHAT)
RHSA-2016:2574 (REDHAT)
CVE: CVE-2016-2543
CVE: CVE-2016-2543
Id:
CVE-2016-2543
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2543
Comment
: The snd_seq_ioctl_remove_events function in sound/core/seq/seq_clientmgr.c in the Linux kernel before 4.4.1 does not verify FIFO assignment before proceeding with FIFO clearing, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a crafted ioctl call.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
6.2
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
CWE-Other ()
References:
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.1 (CONFIRM)
[oss-security] 20160119 Security bugs in Linux kernel sound subsystem (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=1311554 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=030e2c78d3a91dd0d27fef37e91950dde333eba1 (CONFIRM)
https://github.com/torvalds/linux/commit/030e2c78d3a91dd0d27fef37e91950dde333eba1 (CONFIRM)
SUSE-SU-2016:2074 (SUSE)
83377 (BID)
DSA-3503 (DEBIAN)
USN-2967-1 (UBUNTU)
USN-2967-2 (UBUNTU)
USN-2930-1 (UBUNTU)
USN-2931-1 (UBUNTU)
USN-2929-1 (UBUNTU)
USN-2932-1 (UBUNTU)
USN-2930-3 (UBUNTU)
USN-2930-2 (UBUNTU)
USN-2929-2 (UBUNTU)
SUSE-SU-2016:0911 (SUSE)
SUSE-SU-2016:1102 (SUSE)
1035304 (SECTRACK)
CVE: CVE-2016-2544
CVE: CVE-2016-2544
Id:
CVE-2016-2544
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2544
Comment
: Race condition in the queue_delete function in sound/core/seq/seq_queue.c in the Linux kernel before 4.4.1 allows local users to cause a denial of service (use-after-free and system crash) by making an ioctl call at a certain time.
CVSSv2 Score:
4.7
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:N/A:C
CVSSv3 Score:
5.1
Attack vector:
LOCAL
Attack complexity:
HIGH
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'))
References:
https://bugzilla.redhat.com/show_bug.cgi?id=1311558 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.1 (CONFIRM)
https://github.com/torvalds/linux/commit/3567eb6af614dac436c4b16a8d426f9faed639b3 (CONFIRM)
[oss-security] 20160119 Security bugs in Linux kernel sound subsystem (MLIST)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=3567eb6af614dac436c4b16a8d426f9faed639b3 (CONFIRM)
SUSE-SU-2016:2074 (SUSE)
83380 (BID)
DSA-3503 (DEBIAN)
USN-2967-1 (UBUNTU)
USN-2967-2 (UBUNTU)
USN-2930-1 (UBUNTU)
USN-2931-1 (UBUNTU)
USN-2929-1 (UBUNTU)
USN-2932-1 (UBUNTU)
USN-2930-3 (UBUNTU)
USN-2930-2 (UBUNTU)
USN-2929-2 (UBUNTU)
SUSE-SU-2016:0911 (SUSE)
SUSE-SU-2016:1102 (SUSE)
1035305 (SECTRACK)
CVE: CVE-2016-2545
CVE: CVE-2016-2545
Id:
CVE-2016-2545
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2545
Comment
: The snd_timer_interrupt function in sound/core/timer.c in the Linux kernel before 4.4.1 does not properly maintain a certain linked list, which allows local users to cause a denial of service (race condition and system crash) via a crafted ioctl call.
CVSSv2 Score:
4.7
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:N/A:C
CVSSv3 Score:
5.1
Attack vector:
LOCAL
Attack complexity:
HIGH
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'))
References:
https://bugzilla.redhat.com/show_bug.cgi?id=1311560 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.1 (CONFIRM)
[oss-security] 20160119 Security bugs in Linux kernel sound subsystem (MLIST)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ee8413b01045c74340aa13ad5bdf905de32be736 (CONFIRM)
https://github.com/torvalds/linux/commit/ee8413b01045c74340aa13ad5bdf905de32be736 (CONFIRM)
83381 (BID)
SUSE-SU-2016:2074 (SUSE)
DSA-3503 (DEBIAN)
USN-2967-1 (UBUNTU)
USN-2967-2 (UBUNTU)
USN-2930-1 (UBUNTU)
USN-2931-1 (UBUNTU)
USN-2929-1 (UBUNTU)
USN-2932-1 (UBUNTU)
USN-2930-3 (UBUNTU)
USN-2930-2 (UBUNTU)
USN-2929-2 (UBUNTU)
SUSE-SU-2016:0911 (SUSE)
SUSE-SU-2016:1102 (SUSE)
1035296 (SECTRACK)
CVE: CVE-2016-2546
CVE: CVE-2016-2546
Id:
CVE-2016-2546
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2546
Comment
: sound/core/timer.c in the Linux kernel before 4.4.1 uses an incorrect type of mutex, which allows local users to cause a denial of service (race condition, use-after-free, and system crash) via a crafted ioctl call.
CVSSv2 Score:
4.7
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:N/A:C
CVSSv3 Score:
5.1
Attack vector:
LOCAL
Attack complexity:
HIGH
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'))
References:
https://bugzilla.redhat.com/show_bug.cgi?id=1311564 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=af368027a49a751d6ff4ee9e3f9961f35bb4fede (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.1 (CONFIRM)
[oss-security] 20160119 Security bugs in Linux kernel sound subsystem (MLIST)
https://github.com/torvalds/linux/commit/af368027a49a751d6ff4ee9e3f9961f35bb4fede (CONFIRM)
83384 (BID)
SUSE-SU-2016:2074 (SUSE)
DSA-3503 (DEBIAN)
USN-2967-1 (UBUNTU)
USN-2967-2 (UBUNTU)
USN-2930-1 (UBUNTU)
USN-2931-1 (UBUNTU)
USN-2929-1 (UBUNTU)
USN-2932-1 (UBUNTU)
USN-2930-3 (UBUNTU)
USN-2930-2 (UBUNTU)
USN-2929-2 (UBUNTU)
SUSE-SU-2016:0911 (SUSE)
SUSE-SU-2016:1102 (SUSE)
1035301 (SECTRACK)
CVE: CVE-2016-2547
CVE: CVE-2016-2547
Id:
CVE-2016-2547
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2547
Comment
: sound/core/timer.c in the Linux kernel before 4.4.1 employs a locking approach that does not consider slave timer instances, which allows local users to cause a denial of service (race condition, use-after-free, and system crash) via a crafted ioctl call.
CVSSv2 Score:
4.7
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:N/A:C
CVSSv3 Score:
5.1
Attack vector:
LOCAL
Attack complexity:
HIGH
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'))
References:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b5a663aa426f4884c71cd8580adae73f33570f0d (CONFIRM)
https://github.com/torvalds/linux/commit/b5a663aa426f4884c71cd8580adae73f33570f0d (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.1 (CONFIRM)
[oss-security] 20160119 Security bugs in Linux kernel sound subsystem (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=1311566 (CONFIRM)
83378 (BID)
SUSE-SU-2016:2074 (SUSE)
DSA-3503 (DEBIAN)
USN-2967-1 (UBUNTU)
USN-2967-2 (UBUNTU)
USN-2930-1 (UBUNTU)
USN-2931-1 (UBUNTU)
USN-2929-1 (UBUNTU)
USN-2932-1 (UBUNTU)
USN-2930-3 (UBUNTU)
USN-2930-2 (UBUNTU)
USN-2929-2 (UBUNTU)
SUSE-SU-2016:0911 (SUSE)
SUSE-SU-2016:1102 (SUSE)
1035298 (SECTRACK)
CVE: CVE-2016-2548
CVE: CVE-2016-2548
Id:
CVE-2016-2548
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2548
Comment
: sound/core/timer.c in the Linux kernel before 4.4.1 retains certain linked lists after a close or stop action, which allows local users to cause a denial of service (system crash) via a crafted ioctl call, related to the (1) snd_timer_close and (2) _snd_timer_stop functions.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
6.2
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
20 (Improper Input Validation)
References:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b5a663aa426f4884c71cd8580adae73f33570f0d (CONFIRM)
https://github.com/torvalds/linux/commit/b5a663aa426f4884c71cd8580adae73f33570f0d (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.1 (CONFIRM)
[oss-security] 20160119 Security bugs in Linux kernel sound subsystem (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=1311568 (CONFIRM)
SUSE-SU-2016:2074 (SUSE)
83383 (BID)
DSA-3503 (DEBIAN)
USN-2967-1 (UBUNTU)
USN-2967-2 (UBUNTU)
USN-2930-1 (UBUNTU)
USN-2931-1 (UBUNTU)
USN-2929-1 (UBUNTU)
USN-2932-1 (UBUNTU)
USN-2930-3 (UBUNTU)
USN-2930-2 (UBUNTU)
USN-2929-2 (UBUNTU)
SUSE-SU-2016:0911 (SUSE)
SUSE-SU-2016:1102 (SUSE)
1035306 (SECTRACK)
CVE: CVE-2016-2549
CVE: CVE-2016-2549
Id:
CVE-2016-2549
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2549
Comment
: sound/core/hrtimer.c in the Linux kernel before 4.4.1 does not prevent recursive callback access, which allows local users to cause a denial of service (deadlock) via a crafted ioctl call.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
6.2
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
20 (Improper Input Validation)
References:
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.1 (CONFIRM)
[oss-security] 20160119 Security bugs in Linux kernel sound subsystem (MLIST)
https://github.com/torvalds/linux/commit/2ba1fe7a06d3624f9a7586d672b55f08f7c670f3 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1311570 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2ba1fe7a06d3624f9a7586d672b55f08f7c670f3 (CONFIRM)
SUSE-SU-2016:2074 (SUSE)
83382 (BID)
DSA-3503 (DEBIAN)
USN-2967-1 (UBUNTU)
USN-2967-2 (UBUNTU)
USN-2930-1 (UBUNTU)
USN-2931-1 (UBUNTU)
USN-2929-1 (UBUNTU)
USN-2932-1 (UBUNTU)
USN-2930-3 (UBUNTU)
USN-2930-2 (UBUNTU)
USN-2929-2 (UBUNTU)
SUSE-SU-2016:0911 (SUSE)
SUSE-SU-2016:1102 (SUSE)
CVE: CVE-2016-2782
CVE: CVE-2016-2782
Id:
CVE-2016-2782
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2782
Comment
: The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a (1) bulk-in or (2) interrupt-in endpoint.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
4.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
476 (NULL Pointer Dereference)
References:
https://github.com/torvalds/linux/commit/cac9b50b0d75a1d50d6c056ff65c005f3224c8e0 (CONFIRM)
[oss-security] 20160228 Re: CVE request -- linux kernel: visor: crash on invalid USB device descriptors in treo_attach() in visor driver (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=1312670 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cac9b50b0d75a1d50d6c056ff65c005f3224c8e0 (CONFIRM)
SUSE-SU-2016:1672 (SUSE)
SUSE-SU-2016:1690 (SUSE)
SUSE-SU-2016:1707 (SUSE)
SUSE-SU-2016:1764 (SUSE)
SUSE-SU-2016:2074 (SUSE)
USN-2967-1 (UBUNTU)
USN-2967-2 (UBUNTU)
USN-2930-1 (UBUNTU)
USN-2929-1 (UBUNTU)
USN-2932-1 (UBUNTU)
USN-2948-2 (UBUNTU)
SUSE-SU-2016:1019 (SUSE)
USN-2930-3 (UBUNTU)
USN-2930-2 (UBUNTU)
USN-2929-2 (UBUNTU)
USN-2948-1 (UBUNTU)
39539 (EXPLOIT-DB)
CVE: CVE-2016-2847
CVE: CVE-2016-2847
Id:
CVE-2016-2847
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2847
Comment
: fs/pipe.c in the Linux kernel before 4.5 does not limit the amount of unread data in pipes, which allows local users to cause a denial of service (memory consumption) by creating many pipes with non-default sizes.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
6.2
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
399 (Resource Management Errors)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=1313428 (CONFIRM)
[oss-security] 20160301 CVE request -- linux kernel: pipe: limit the per-user amount of pages allocated in pipes (MLIST)
https://github.com/torvalds/linux/commit/759c01142a5d0f364a462346168a56de28a80f52 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=759c01142a5d0f364a462346168a56de28a80f52 (CONFIRM)
SUSE-SU-2016:1672 (SUSE)
SUSE-SU-2016:1696 (SUSE)
SUSE-SU-2016:1690 (SUSE)
SUSE-SU-2016:1707 (SUSE)
SUSE-SU-2016:1937 (SUSE)
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html (CONFIRM)
http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html (CONFIRM)
83870 (BID)
SUSE-SU-2016:2074 (SUSE)
openSUSE-SU-2016:1382 (SUSE)
DSA-3503 (DEBIAN)
USN-2967-1 (UBUNTU)
USN-2967-2 (UBUNTU)
USN-2946-2 (UBUNTU)
USN-2947-3 (UBUNTU)
USN-2948-2 (UBUNTU)
USN-2947-1 (UBUNTU)
USN-2949-1 (UBUNTU)
USN-2947-2 (UBUNTU)
USN-2946-1 (UBUNTU)
USN-2948-1 (UBUNTU)
RHSA-2017:0217 (REDHAT)
RHSA-2016:2584 (REDHAT)
RHSA-2016:2574 (REDHAT)
CVE: CVE-2016-3134
CVE: CVE-2016-3134
Id:
CVE-2016-3134
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3134
Comment
: The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
8.4
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE:
119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)
References:
SUSE-SU-2016:1690 ()
https://github.com/torvalds/linux/commit/54d83fc74aa9ec72794373cb47432c5f7fb1a309 ()
https://code.google.com/p/google-security-research/issues/detail?id=758 ()
SUSE-SU-2016:2010 ()
USN-2930-1 ()
SUSE-SU-2016:1696 ()
https://bugzilla.redhat.com/show_bug.cgi?id=1317383 ()
SUSE-SU-2016:1994 ()
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html ()
SUSE-SU-2016:1961 ()
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html ()
USN-2930-2 ()
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=54d83fc74aa9ec72794373cb47432c5f7fb1a309 ()
SUSE-SU-2016:2001 ()
SUSE-SU-2016:1985 ()
RHSA-2016:1847 ()
SUSE-SU-2016:2006 ()
USN-3049-1 ()
RHSA-2016:1875 ()
SUSE-SU-2016:2014 ()
openSUSE-SU-2016:1641 ()
SUSE-SU-2016:1764 ()
USN-2930-3 ()
DSA-3607 ()
1036763 ()
SUSE-SU-2016:1672 ()
SUSE-SU-2016:2009 ()
USN-2929-1 ()
USN-2932-1 ()
USN-3050-1 ()
SUSE-SU-2016:2005 ()
SUSE-SU-2016:2007 ()
SUSE-SU-2016:2074 ()
http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html ()
SUSE-SU-2016:2000 ()
RHSA-2016:1883 ()
SUSE-SU-2016:1995 ()
SUSE-SU-2016:2002 ()
USN-2931-1 ()
USN-2929-2 ()
84305 ()
CVE: CVE-2016-3136
CVE: CVE-2016-3136
Id:
CVE-2016-3136
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3136
Comment
: The mct_u232_msr_to_state function in drivers/usb/serial/mct_u232.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted USB device without two interrupt-in endpoint descriptors.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
4.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
CWE-Other ()
References:
USN-2971-2 ()
SUSE-SU-2016:1690 ()
SUSE-SU-2016:1696 ()
USN-2970-1 ()
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=4e9a0b05257f29cf4b75f3209243ed71614d062e ()
https://bugzilla.redhat.com/show_bug.cgi?id=1283370 ()
USN-2968-1 ()
[oss-security] 20160314 Re: CVE request -- linux kernel: crash on invalid USB device descriptors (mct_u232 driver) ()
https://github.com/torvalds/linux/commit/4e9a0b05257f29cf4b75f3209243ed71614d062e ()
USN-2971-3 ()
USN-2997-1 ()
SUSE-SU-2016:1764 ()
USN-3000-1 ()
DSA-3607 ()
39541 ()
USN-2971-1 ()
https://bugzilla.redhat.com/show_bug.cgi?id=1317007 ()
USN-2996-1 ()
USN-2968-2 ()
openSUSE-SU-2016:1382 ()
84299 ()
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.1 ()
CVE: CVE-2016-3137
CVE: CVE-2016-3137
Id:
CVE-2016-3137
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3137
Comment
: drivers/usb/serial/cypress_m8.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both an interrupt-in and an interrupt-out endpoint descriptor, related to the cypress_generic_port_probe and cypress_open functions.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
4.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
CWE-Other ()
References:
USN-2971-2 ()
SUSE-SU-2016:1690 ()
[oss-security] 20160314 Re: CVE request -- linux kernel: crash on invalid USB device descriptors (cypress_m8 driver) ()
https://bugzilla.redhat.com/show_bug.cgi?id=1316996 ()
SUSE-SU-2016:1696 ()
USN-2970-1 ()
https://github.com/torvalds/linux/commit/c55aee1bf0e6b6feec8b2927b43f7a09a6d5f754 ()
84300 ()
USN-2968-1 ()
USN-2971-3 ()
USN-2997-1 ()
SUSE-SU-2016:1764 ()
USN-3000-1 ()
DSA-3607 ()
USN-2971-1 ()
SUSE-SU-2016:1707 ()
USN-2996-1 ()
SUSE-SU-2016:1672 ()
USN-2968-2 ()
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c55aee1bf0e6b6feec8b2927b43f7a09a6d5f754 ()
openSUSE-SU-2016:1382 ()
SUSE-SU-2016:2074 ()
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.1 ()
CVE: CVE-2016-3138
CVE: CVE-2016-3138
Id:
CVE-2016-3138
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3138
Comment
: The acm_probe function in drivers/usb/class/cdc-acm.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both a control and a data endpoint descriptor.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
4.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
CWE-Other ()
References:
USN-2971-2 ()
SUSE-SU-2016:1690 ()
SUSE-SU-2016:1696 ()
USN-2970-1 ()
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8835ba4a39cf53f705417b3b3a94eb067673f2c9 ()
USN-2969-1 ()
USN-2968-1 ()
USN-2971-3 ()
USN-2997-1 ()
SUSE-SU-2016:1764 ()
DSA-3607 ()
USN-2971-1 ()
[oss-security] 20160314 Re: CVE request -- linux kernel: crash on invalid USB device descriptors (cdc_acm driver) ()
SUSE-SU-2016:1707 ()
USN-2996-1 ()
SUSE-SU-2016:1672 ()
USN-2968-2 ()
https://bugzilla.redhat.com/show_bug.cgi?id=1316204 ()
openSUSE-SU-2016:1382 ()
SUSE-SU-2016:2074 ()
https://github.com/torvalds/linux/commit/8835ba4a39cf53f705417b3b3a94eb067673f2c9 ()
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.1 ()
CVE: CVE-2016-3139
CVE: CVE-2016-3139
Id:
CVE-2016-3139
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3139
Comment
: The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
4.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
CWE-Other ()
References:
39538 ()
SUSE-SU-2016:1690 ()
https://bugzilla.redhat.com/show_bug.cgi?id=1316993 ()
https://bugzilla.redhat.com/show_bug.cgi?id=1283377 ()
https://security-tracker.debian.org/tracker/CVE-2016-3139 ()
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=471d17148c8b4174ac5f5283a73316d12c4379bc ()
SUSE-SU-2016:1764 ()
https://github.com/torvalds/linux/commit/471d17148c8b4174ac5f5283a73316d12c4379bc ()
https://bugzilla.redhat.com/show_bug.cgi?id=1283375 ()
SUSE-SU-2016:1707 ()
SUSE-SU-2016:1672 ()
SUSE-SU-2016:1019 ()
SUSE-SU-2016:2074 ()
CVE: CVE-2016-3140
CVE: CVE-2016-3140
Id:
CVE-2016-3140
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3140
Comment
: The digi_port_init function in drivers/usb/serial/digi_acceleport.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
4.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
CWE-Other ()
References:
USN-2971-2 ()
SUSE-SU-2016:1690 ()
39537 ()
SUSE-SU-2016:1696 ()
USN-2970-1 ()
https://bugzilla.redhat.com/show_bug.cgi?id=1316995 ()
USN-2968-1 ()
USN-2971-3 ()
USN-2997-1 ()
SUSE-SU-2016:1764 ()
USN-3000-1 ()
DSA-3607 ()
USN-2971-1 ()
https://github.com/torvalds/linux/commit/5a07975ad0a36708c6b0a5b9fea1ff811d0b0c1f ()
SUSE-SU-2016:1707 ()
USN-2996-1 ()
SUSE-SU-2016:1672 ()
USN-2968-2 ()
openSUSE-SU-2016:1382 ()
SUSE-SU-2016:2074 ()
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=5a07975ad0a36708c6b0a5b9fea1ff811d0b0c1f ()
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.1 ()
84304 ()
[oss-security] 20160314 Re: CVE request -- linux kernel: crash on invalid USB device descriptors (digi_acceleport driver) ()
CVE: CVE-2016-3156
CVE: CVE-2016-3156
Id:
CVE-2016-3156
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3156
Comment
: The IPv4 implementation in the Linux kernel before 4.5.2 mishandles destruction of device objects, which allows guest OS users to cause a denial of service (host OS networking outage) by arranging for a large number of IP addresses.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
399 (Resource Management Errors)
References:
[oss-security] 20160315 CVE request: ipv4: Don't do expensive useless work during inetdev destroy (MLIST)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=fbd40ea0180a2d328c5adc61414dc8bab9335ce2 (CONFIRM)
https://github.com/torvalds/linux/commit/fbd40ea0180a2d328c5adc61414dc8bab9335ce2 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1318172 (CONFIRM)
USN-2997-1 (UBUNTU)
USN-2996-1 (UBUNTU)
SUSE-SU-2016:1672 (SUSE)
SUSE-SU-2016:1690 (SUSE)
SUSE-SU-2016:1707 (SUSE)
SUSE-SU-2016:1764 (SUSE)
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html (CONFIRM)
http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html (CONFIRM)
DSA-3607 (DEBIAN)
SUSE-SU-2016:2074 (SUSE)
84428 (BID)
openSUSE-SU-2016:1382 (SUSE)
USN-2968-1 (UBUNTU)
USN-2969-1 (UBUNTU)
USN-2971-1 (UBUNTU)
USN-2971-2 (UBUNTU)
USN-2970-1 (UBUNTU)
USN-2971-3 (UBUNTU)
USN-2968-2 (UBUNTU)
SUSE-SU-2016:1019 (SUSE)
RHSA-2016:2584 (REDHAT)
RHSA-2016:2574 (REDHAT)
CVE: CVE-2016-3672
CVE: CVE-2016-3672
Id:
CVE-2016-3672
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3672
Comment
: The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local users to defeat the intended restrictions on the ADDR_NO_RANDOMIZE flag, and bypass the ASLR protection mechanism for a setuid or setgid program, by disabling stack-consumption resource limits.
CVSSv2 Score:
4.6
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:P
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
254 (Security Features)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=1324749 (CONFIRM)
https://github.com/torvalds/linux/commit/8b8addf891de8a00e4d39fc32f93f7c5eb8feceb (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8b8addf891de8a00e4d39fc32f93f7c5eb8feceb (CONFIRM)
USN-2997-1 (UBUNTU)
USN-2996-1 (UBUNTU)
USN-3000-1 (UBUNTU)
USN-2998-1 (UBUNTU)
USN-3002-1 (UBUNTU)
USN-3003-1 (UBUNTU)
USN-3001-1 (UBUNTU)
USN-3004-1 (UBUNTU)
USN-2989-1 (UBUNTU)
SUSE-SU-2016:1690 (SUSE)
SUSE-SU-2016:1937 (SUSE)
openSUSE-SU-2016:1641 (SUSE)
openSUSE-SU-2016:2184 (SUSE)
85884 (BID)
DSA-3607 (DEBIAN)
SUSE-SU-2016:2105 (SUSE)
http://hmarco.org/bugs/CVE-2016-3672-Unlimiting-the-stack-not-longer-dis (MISC)
20160406 CVE-2016-3672 - Unlimiting the stack not longer disables ASLR (FULLDISC)
FEDORA-2016-76706f51a7 (FEDORA)
39669 (EXPLOIT-DB)
http://hmarco.org/bugs/CVE-2016-3672-Unlimiting-the-stack-not-longer-disables-ASLR.html (MISC)
1035506 (SECTRACK)
RHSA-2018:1062 (REDHAT)
RHSA-2018:0676 (REDHAT)
20160406 CVE-2016-3672 - Unlimiting the stack not longer disables ASLR (BUGTRAQ)
CVE: CVE-2016-3689
CVE: CVE-2016-3689
Id:
CVE-2016-3689
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3689
Comment
: The ims_pcu_parse_cdc_data function in drivers/input/misc/ims-pcu.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (system crash) via a USB device without both a master and a slave interface.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
4.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
CWE-Other ()
References:
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.1 (CONFIRM)
https://bugzilla.novell.com/show_bug.cgi?id=971628 (CONFIRM)
[oss-security] 20160330 Re: CVE request -- linux kernel: crash on invalid USB device descriptors (ims-pcu driver) (MLIST)
https://github.com/torvalds/linux/commit/a0ad220c96692eda76b2e3fd7279f3dcd1d8a8ff (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a0ad220c96692eda76b2e3fd7279f3dcd1d8a8ff (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1320060 (CONFIRM)
USN-3000-1 (UBUNTU)
SUSE-SU-2016:1696 (SUSE)
SUSE-SU-2016:1690 (SUSE)
SUSE-SU-2016:1764 (SUSE)
openSUSE-SU-2016:1382 (SUSE)
USN-2968-1 (UBUNTU)
USN-2971-1 (UBUNTU)
USN-2971-2 (UBUNTU)
USN-2970-1 (UBUNTU)
USN-2971-3 (UBUNTU)
USN-2968-2 (UBUNTU)
1035441 (SECTRACK)
CVE: CVE-2016-3951
CVE: CVE-2016-3951
Id:
CVE-2016-3951
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3951
Comment
: Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified other impact by inserting a USB device with an invalid USB descriptor.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
4.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
CWE-Other ()
References:
https://github.com/torvalds/linux/commit/4d06dd537f95683aba3651098ae288b7cbff8274 (CONFIRM)
https://github.com/torvalds/linux/commit/1666984c8625b3db19a9abc298931d35ab7bc64b (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1666984c8625b3db19a9abc298931d35ab7bc64b (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=4d06dd537f95683aba3651098ae288b7cbff8274 (CONFIRM)
[oss-security] 20160406 Fwd: CVE Request: Linux: usbnet: memory corruption triggered by invalid USB descriptor (MLIST)
[netdev] 20160304 Re: Possible double-free in the usbnet driver (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=1324782 (CONFIRM)
USN-3002-1 (UBUNTU)
USN-3001-1 (UBUNTU)
USN-3004-1 (UBUNTU)
USN-2989-1 (UBUNTU)
USN-3000-1 (UBUNTU)
USN-2998-1 (UBUNTU)
USN-3003-1 (UBUNTU)
USN-3021-1 (UBUNTU)
USN-3021-2 (UBUNTU)
SUSE-SU-2016:1696 (SUSE)
SUSE-SU-2016:1690 (SUSE)
SUSE-SU-2016:1764 (SUSE)
91028 (BID)
DSA-3607 (DEBIAN)
openSUSE-SU-2016:1382 (SUSE)
1036763 (SECTRACK)
CVE: CVE-2016-4470
CVE: CVE-2016-4470
Id:
CVE-2016-4470
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4470
Comment
: The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a crafted keyctl request2 command.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
CWE-Other ()
References:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=38327424b40bcebe2de92d07312c89360ac9229a (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1341716 (CONFIRM)
https://github.com/torvalds/linux/commit/38327424b40bcebe2de92d07312c89360ac9229a (CONFIRM)
[oss-security] 20160615 CVE-2016-4470: Linux kernel Uninitialized variable in request_key handling user controlled kfree(). (MLIST)
RHSA-2016:1532 (REDHAT)
RHSA-2016:1541 (REDHAT)
RHSA-2016:1539 (REDHAT)
SUSE-SU-2016:1937 (SUSE)
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html (CONFIRM)
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html (CONFIRM)
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html (CONFIRM)
SUSE-SU-2016:1995 (SUSE)
USN-3052-1 (UBUNTU)
SUSE-SU-2016:2000 (SUSE)
RHSA-2016:1657 (REDHAT)
SUSE-SU-2016:2002 (SUSE)
SUSE-SU-2016:1998 (SUSE)
USN-3055-1 (UBUNTU)
DSA-3607 (DEBIAN)
USN-3050-1 (UBUNTU)
SUSE-SU-2016:1961 (SUSE)
SUSE-SU-2016:2014 (SUSE)
SUSE-SU-2016:2006 (SUSE)
USN-3049-1 (UBUNTU)
USN-3053-1 (UBUNTU)
SUSE-SU-2016:2007 (SUSE)
SUSE-SU-2016:1985 (SUSE)
SUSE-SU-2016:2010 (SUSE)
openSUSE-SU-2016:2184 (SUSE)
SUSE-SU-2016:1999 (SUSE)
SUSE-SU-2016:2001 (SUSE)
SUSE-SU-2016:1994 (SUSE)
USN-3056-1 (UBUNTU)
SUSE-SU-2016:2003 (SUSE)
SUSE-SU-2016:2011 (SUSE)
USN-3057-1 (UBUNTU)
SUSE-SU-2016:2005 (SUSE)
SUSE-SU-2016:2105 (SUSE)
SUSE-SU-2016:2009 (SUSE)
SUSE-SU-2016:2018 (SUSE)
USN-3051-1 (UBUNTU)
USN-3054-1 (UBUNTU)
1036763 (SECTRACK)
RHSA-2016:2133 (REDHAT)
RHSA-2016:2128 (REDHAT)
RHSA-2016:2076 (REDHAT)
RHSA-2016:2074 (REDHAT)
RHSA-2016:2006 (REDHAT)
CVE: CVE-2016-4482
CVE: CVE-2016-4482
Id:
CVE-2016-4482
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4482
Comment
: The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl call.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CVSSv3 Score:
6.2
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE:
200 (Information Exposure)
References:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=681fef8380eb818c0b845fca5d2ab1dcbab114ee (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1332931 (CONFIRM)
[oss-security] 20160503 CVE Request: information leak in devio of Linux kernel (MLIST)
https://github.com/torvalds/linux/commit/681fef8380eb818c0b845fca5d2ab1dcbab114ee (CONFIRM)
FEDORA-2016-4ce97823af (FEDORA)
USN-3017-2 (UBUNTU)
USN-3018-2 (UBUNTU)
USN-3016-4 (UBUNTU)
USN-3016-1 (UBUNTU)
USN-3016-2 (UBUNTU)
USN-3016-3 (UBUNTU)
USN-3018-1 (UBUNTU)
USN-3019-1 (UBUNTU)
USN-3017-3 (UBUNTU)
USN-3020-1 (UBUNTU)
USN-3017-1 (UBUNTU)
USN-3021-1 (UBUNTU)
USN-3021-2 (UBUNTU)
SUSE-SU-2016:1672 (SUSE)
SUSE-SU-2016:1696 (SUSE)
SUSE-SU-2016:1690 (SUSE)
SUSE-SU-2016:1937 (SUSE)
DSA-3607 (DEBIAN)
SUSE-SU-2016:1985 (SUSE)
openSUSE-SU-2016:1641 (SUSE)
openSUSE-SU-2016:2184 (SUSE)
90029 (BID)
SUSE-SU-2016:2105 (SUSE)
CVE: CVE-2016-4485
CVE: CVE-2016-4485
Id:
CVE-2016-4485
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4485
Comment
: The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message.
CVSSv2 Score:
5
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N
CVSSv3 Score:
7.5
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE:
200 (Information Exposure)
References:
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.5 (CONFIRM)
[oss-security] 20160503 CVE Request: kernel information leak vulnerability in llc module (MLIST)
https://github.com/torvalds/linux/commit/b8670c09f37bdf2847cc44f36511a53afc6161fd (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b8670c09f37bdf2847cc44f36511a53afc6161fd (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1333309 (CONFIRM)
USN-2997-1 (UBUNTU)
USN-2996-1 (UBUNTU)
USN-3002-1 (UBUNTU)
USN-3001-1 (UBUNTU)
USN-3004-1 (UBUNTU)
USN-2989-1 (UBUNTU)
USN-3000-1 (UBUNTU)
USN-2998-1 (UBUNTU)
USN-3003-1 (UBUNTU)
USN-3005-1 (UBUNTU)
USN-3007-1 (UBUNTU)
SUSE-SU-2016:1672 (SUSE)
USN-3006-1 (UBUNTU)
openSUSE-SU-2016:1641 (SUSE)
DSA-3607 (DEBIAN)
90015 (BID)
SUSE-SU-2016:1985 (SUSE)
CVE: CVE-2016-4486
CVE: CVE-2016-4486
Id:
CVE-2016-4486
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4486
Comment
: The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CVSSv3 Score:
3.3
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
LOW
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20160504 CVE Request: kernel information leak vulnerability in rtnetlink (MLIST)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=5f8e44741f9f216e33736ea4ec65ca9ac03036e6 (CONFIRM)
https://github.com/torvalds/linux/commit/5f8e44741f9f216e33736ea4ec65ca9ac03036e6 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1333316 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.5 (CONFIRM)
USN-2997-1 (UBUNTU)
USN-2996-1 (UBUNTU)
USN-3002-1 (UBUNTU)
USN-3001-1 (UBUNTU)
USN-3004-1 (UBUNTU)
USN-2989-1 (UBUNTU)
USN-3000-1 (UBUNTU)
USN-2998-1 (UBUNTU)
USN-3003-1 (UBUNTU)
USN-3005-1 (UBUNTU)
USN-3007-1 (UBUNTU)
SUSE-SU-2016:1672 (SUSE)
SUSE-SU-2016:1696 (SUSE)
SUSE-SU-2016:1690 (SUSE)
USN-3006-1 (UBUNTU)
SUSE-SU-2016:1937 (SUSE)
DSA-3607 (DEBIAN)
SUSE-SU-2016:2074 (SUSE)
90051 (BID)
SUSE-SU-2016:1985 (SUSE)
openSUSE-SU-2016:1641 (SUSE)
openSUSE-SU-2016:2184 (SUSE)
SUSE-SU-2016:2105 (SUSE)
46006 (EXPLOIT-DB)
CVE: CVE-2016-4565
CVE: CVE-2016-4565
Id:
CVE-2016-4565
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4565
Comment
: The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI interface.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
264 (Permissions, Privileges, and Access Controls)
References:
https://github.com/torvalds/linux/commit/e6bd18f57aad1a2d1ef40e646d03ed0f2515c9e3 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.3 (CONFIRM)
[oss-security] 20160507 CVE Request: Linux: IB/security: Restrict use of the write() interface' (MLIST)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e6bd18f57aad1a2d1ef40e646d03ed0f2515c9e3 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1310570 (CONFIRM)
USN-3018-1 (UBUNTU)
USN-3019-1 (UBUNTU)
USN-3018-2 (UBUNTU)
RHSA-2016:1341 (REDHAT)
RHSA-2016:1277 (REDHAT)
RHSA-2016:1301 (REDHAT)
USN-3002-1 (UBUNTU)
USN-3001-1 (UBUNTU)
USN-3004-1 (UBUNTU)
USN-3003-1 (UBUNTU)
USN-3021-1 (UBUNTU)
USN-3005-1 (UBUNTU)
USN-3021-2 (UBUNTU)
USN-3007-1 (UBUNTU)
SUSE-SU-2016:1672 (SUSE)
SUSE-SU-2016:1690 (SUSE)
USN-3006-1 (UBUNTU)
SUSE-SU-2016:1937 (SUSE)
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html (CONFIRM)
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html (CONFIRM)
http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html (CONFIRM)
SUSE-SU-2016:1995 (SUSE)
SUSE-SU-2016:2000 (SUSE)
90301 (BID)
DSA-3607 (DEBIAN)
SUSE-SU-2016:2014 (SUSE)
SUSE-SU-2016:2010 (SUSE)
openSUSE-SU-2016:1641 (SUSE)
SUSE-SU-2016:2001 (SUSE)
SUSE-SU-2016:1994 (SUSE)
RHSA-2016:1617 (REDHAT)
SUSE-SU-2016:2011 (SUSE)
RHSA-2016:1581 (REDHAT)
RHSA-2016:1657 (REDHAT)
SUSE-SU-2016:2002 (SUSE)
SUSE-SU-2016:1961 (SUSE)
SUSE-SU-2016:2006 (SUSE)
RHSA-2016:1489 (REDHAT)
SUSE-SU-2016:2007 (SUSE)
SUSE-SU-2016:1985 (SUSE)
openSUSE-SU-2016:2184 (SUSE)
RHSA-2016:1640 (REDHAT)
SUSE-SU-2016:2003 (SUSE)
SUSE-SU-2016:2005 (SUSE)
SUSE-SU-2016:2105 (SUSE)
RHSA-2016:1814 (REDHAT)
SUSE-SU-2016:2009 (SUSE)
RHSA-2016:1406 (REDHAT)
CVE: CVE-2016-4569
CVE: CVE-2016-4569
Id:
CVE-2016-4569
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4569
Comment
: The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE:
200 (Information Exposure)
References:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cec8f96e49d9be372fdb0c3836dcf31ec71e457e (CONFIRM)
https://github.com/torvalds/linux/commit/cec8f96e49d9be372fdb0c3836dcf31ec71e457e (CONFIRM)
[oss-security] 20160509 Re: CVE Request: kernel information leak vulnerability in Linux sound module (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=1334643 (CONFIRM)
USN-3017-2 (UBUNTU)
USN-3018-2 (UBUNTU)
USN-3016-4 (UBUNTU)
USN-3016-1 (UBUNTU)
USN-3016-2 (UBUNTU)
USN-3016-3 (UBUNTU)
USN-3018-1 (UBUNTU)
USN-3019-1 (UBUNTU)
USN-3017-3 (UBUNTU)
USN-3020-1 (UBUNTU)
USN-3017-1 (UBUNTU)
USN-3021-1 (UBUNTU)
USN-3021-2 (UBUNTU)
SUSE-SU-2016:1672 (SUSE)
SUSE-SU-2016:1696 (SUSE)
SUSE-SU-2016:1690 (SUSE)
SUSE-SU-2016:1937 (SUSE)
DSA-3607 (DEBIAN)
SUSE-SU-2016:1985 (SUSE)
openSUSE-SU-2016:1641 (SUSE)
openSUSE-SU-2016:2184 (SUSE)
90347 (BID)
SUSE-SU-2016:2105 (SUSE)
RHSA-2016:2584 (REDHAT)
RHSA-2016:2574 (REDHAT)
CVE: CVE-2016-4578
CVE: CVE-2016-4578
Id:
CVE-2016-4578
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4578
Comment
: sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface, related to the (1) snd_timer_user_ccallback and (2) snd_timer_user_tinterrupt functions.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE:
200 (Information Exposure)
References:
https://github.com/torvalds/linux/commit/9a47e9cff994f37f7f0dbd9ae23740d0f64f9fe6 (CONFIRM)
https://github.com/torvalds/linux/commit/e4ec8cc8039a7063e24204299b462bd1383184a5 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1335215 (CONFIRM)
[oss-security] 20160511 Re: CVE Request: alsa: kernel information leak vulnerability in Linux sound/core/timer (MLIST)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e4ec8cc8039a7063e24204299b462bd1383184a5 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=9a47e9cff994f37f7f0dbd9ae23740d0f64f9fe6 (CONFIRM)
USN-3017-2 (UBUNTU)
USN-3018-2 (UBUNTU)
USN-3016-4 (UBUNTU)
USN-3016-1 (UBUNTU)
USN-3016-2 (UBUNTU)
USN-3016-3 (UBUNTU)
USN-3018-1 (UBUNTU)
USN-3019-1 (UBUNTU)
USN-3017-3 (UBUNTU)
USN-3020-1 (UBUNTU)
USN-3017-1 (UBUNTU)
USN-3021-1 (UBUNTU)
USN-3021-2 (UBUNTU)
SUSE-SU-2016:1672 (SUSE)
SUSE-SU-2016:1690 (SUSE)
SUSE-SU-2016:1937 (SUSE)
DSA-3607 (DEBIAN)
SUSE-SU-2016:1985 (SUSE)
openSUSE-SU-2016:1641 (SUSE)
openSUSE-SU-2016:2184 (SUSE)
SUSE-SU-2016:2105 (SUSE)
90535 (BID)
RHSA-2016:2584 (REDHAT)
RHSA-2016:2574 (REDHAT)
46529 (EXPLOIT-DB)
CVE: CVE-2016-4580
CVE: CVE-2016-4580
Id:
CVE-2016-4580
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4580
Comment
: The x25_negotiate_facilities function in net/x25/x25_facilities.c in the Linux kernel before 4.5.5 does not properly initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory via an X.25 Call Request.
CVSSv2 Score:
5
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N
CVSSv3 Score:
7.5
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE:
200 (Information Exposure)
References:
https://github.com/torvalds/linux/commit/79e48650320e6fba48369fccf13fd045315b19b8 (CONFIRM)
[oss-security] 20160510 CVE Request: x25: a kernel infoleak in x25_negotiate_facilities() (MLIST)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.5 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=79e48650320e6fba48369fccf13fd045315b19b8 (CONFIRM)
USN-3017-2 (UBUNTU)
USN-3018-2 (UBUNTU)
USN-3016-4 (UBUNTU)
USN-3016-1 (UBUNTU)
USN-3016-2 (UBUNTU)
USN-3016-3 (UBUNTU)
USN-3018-1 (UBUNTU)
USN-3019-1 (UBUNTU)
USN-3017-3 (UBUNTU)
USN-3020-1 (UBUNTU)
USN-3017-1 (UBUNTU)
USN-3021-1 (UBUNTU)
USN-3021-2 (UBUNTU)
SUSE-SU-2016:1672 (SUSE)
openSUSE-SU-2016:1641 (SUSE)
90528 (BID)
DSA-3607 (DEBIAN)
SUSE-SU-2016:1985 (SUSE)
CVE: CVE-2016-4581
CVE: CVE-2016-4581
Id:
CVE-2016-4581
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4581
Comment
: fs/pnode.c in the Linux kernel before 4.5.4 does not properly traverse a mount propagation tree in a certain case involving a slave mount, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a crafted series of mount system calls.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
CWE-Other ()
References:
[oss-security] 20160511 CVE request: Mishandling the first propagated copy being a slave (MLIST)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.4 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1333712 (CONFIRM)
https://github.com/torvalds/linux/commit/5ec0811d30378ae104f250bfc9b3640242d81e3f (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=5ec0811d30378ae104f250bfc9b3640242d81e3f (CONFIRM)
USN-3000-1 (UBUNTU)
USN-2998-1 (UBUNTU)
USN-3002-1 (UBUNTU)
USN-3003-1 (UBUNTU)
USN-3001-1 (UBUNTU)
USN-3004-1 (UBUNTU)
USN-2989-1 (UBUNTU)
USN-3005-1 (UBUNTU)
USN-3007-1 (UBUNTU)
USN-3006-1 (UBUNTU)
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html (CONFIRM)
http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html (CONFIRM)
openSUSE-SU-2016:1641 (SUSE)
90607 (BID)
DSA-3607 (DEBIAN)
RHSA-2016:2584 (REDHAT)
RHSA-2016:2574 (REDHAT)
CVE: CVE-2016-4805
CVE: CVE-2016-4805
Id:
CVE-2016-4805
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4805
Comment
: Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a network namespace, related to the ppp_register_net_channel and ppp_unregister_channel functions.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
416 (Use After Free)
References:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1f461dcdd296eecedaffffc6bae2bfa90bd7eb89 (CONFIRM)
https://github.com/torvalds/linux/commit/1f461dcdd296eecedaffffc6bae2bfa90bd7eb89 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1335803 (CONFIRM)
[oss-security] 20160515 Re: CVE Requests: Linux: use-after-free issue for ppp channel (MLIST)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.2 (CONFIRM)
USN-3021-1 (UBUNTU)
SUSE-SU-2016:1672 (SUSE)
SUSE-SU-2016:1690 (SUSE)
USN-3021-2 (UBUNTU)
SUSE-SU-2016:1937 (SUSE)
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html (CONFIRM)
http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html (CONFIRM)
openSUSE-SU-2016:1641 (SUSE)
openSUSE-SU-2016:2184 (SUSE)
DSA-3607 (DEBIAN)
SUSE-SU-2016:2105 (SUSE)
90605 (BID)
SUSE-SU-2016:1985 (SUSE)
1036763 (SECTRACK)
CVE: CVE-2016-4913
CVE: CVE-2016-4913
Id:
CVE-2016-4913
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4913
Comment
: The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have unspecified other impact via a crafted isofs filesystem.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
200 (Information Exposure)
References:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=99d825822eade8d827a1817357cbf3f889a552d6 (CONFIRM)
[oss-security] 20160518 Re: CVE Request: Linux: information leak in Rock Ridge Extensions to iso9660 -- fs/isofs/rock.c (MLIST)
https://github.com/torvalds/linux/commit/99d825822eade8d827a1817357cbf3f889a552d6 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1337528 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.5 (CONFIRM)
[oss-security] 20160518 CVE Request: Linux: information leak in Rock Ridge Extensions to iso9660 -- fs/isofs/rock.c (MLIST)
USN-3017-2 (UBUNTU)
USN-3018-2 (UBUNTU)
USN-3016-4 (UBUNTU)
USN-3016-1 (UBUNTU)
USN-3016-2 (UBUNTU)
USN-3016-3 (UBUNTU)
USN-3018-1 (UBUNTU)
USN-3019-1 (UBUNTU)
USN-3017-3 (UBUNTU)
USN-3020-1 (UBUNTU)
USN-3017-1 (UBUNTU)
USN-3021-1 (UBUNTU)
USN-3021-2 (UBUNTU)
SUSE-SU-2016:1672 (SUSE)
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html (CONFIRM)
http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html (CONFIRM)
DSA-3607 (DEBIAN)
SUSE-SU-2016:1985 (SUSE)
90730 (BID)
RHSA-2018:3096 (REDHAT)
RHSA-2018:3083 (REDHAT)
CVE: CVE-2016-4997
CVE: CVE-2016-4997
Id:
CVE-2016-4997
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4997
Comment
: The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corruption) by leveraging in-container root access to provide a crafted offset value that triggers an unintended decrement.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
264 (Permissions, Privileges, and Access Controls)
References:
[oss-security] 20160624 Linux CVE-2016-4997 (local privilege escalation) and CVE-2016-4998 (out of bounds memory access) (MLIST)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ce683e5f9d045e5d67d1312a42b359cb2ab2a13c (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.6.3 (CONFIRM)
https://github.com/torvalds/linux/commit/ce683e5f9d045e5d67d1312a42b359cb2ab2a13c (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1349722 (CONFIRM)
USN-3017-2 (UBUNTU)
USN-3018-2 (UBUNTU)
SUSE-SU-2016:1710 (SUSE)
USN-3016-4 (UBUNTU)
USN-3016-1 (UBUNTU)
USN-3016-2 (UBUNTU)
USN-3016-3 (UBUNTU)
USN-3018-1 (UBUNTU)
USN-3019-1 (UBUNTU)
SUSE-SU-2016:1709 (SUSE)
USN-3017-3 (UBUNTU)
USN-3020-1 (UBUNTU)
USN-3017-1 (UBUNTU)
SUSE-SU-2016:1937 (SUSE)
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html (CONFIRM)
[oss-security] 20160929 CVE request - Linux kernel through 4.6.2 allows escalade privileges via IP6T_SO_SET_REPLACE compat setsockopt call (MLIST)
https://github.com/nccgroup/TriforceLinuxSyscallFuzzer/tree/master/crash_reports/report_compatIpt (MISC)
http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html (CONFIRM)
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html (CONFIRM)
SUSE-SU-2016:2181 (SUSE)
SUSE-SU-2016:2179 (SUSE)
DSA-3607 (DEBIAN)
SUSE-SU-2016:2178 (SUSE)
1036171 (SECTRACK)
SUSE-SU-2016:1985 (SUSE)
91451 (BID)
openSUSE-SU-2016:2184 (SUSE)
SUSE-SU-2016:2180 (SUSE)
SUSE-SU-2016:2174 (SUSE)
SUSE-SU-2016:2177 (SUSE)
SUSE-SU-2016:2105 (SUSE)
SUSE-SU-2016:2018 (SUSE)
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05347541 (CONFIRM)
40489 (EXPLOIT-DB)
40435 (EXPLOIT-DB)
RHSA-2016:1883 (REDHAT)
RHSA-2016:1875 (REDHAT)
RHSA-2016:1847 (REDHAT)
CVE: CVE-2016-5244
CVE: CVE-2016-5244
Id:
CVE-2016-5244
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5244
Comment
: The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structure member, which allows remote attackers to obtain sensitive information from kernel stack memory by reading an RDS message.
CVSSv2 Score:
5
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N
CVSSv3 Score:
7.5
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE:
200 (Information Exposure)
References:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=4116def2337991b39919f3b448326e21c40e0dbb (CONFIRM)
https://patchwork.ozlabs.org/patch/629110/ (CONFIRM)
https://github.com/torvalds/linux/commit/4116def2337991b39919f3b448326e21c40e0dbb (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1343337 (CONFIRM)
[oss-security] 20160603 Re: CVE Request: rds: fix an infoleak in rds_inc_info_copy (MLIST)
SUSE-SU-2016:1672 (SUSE)
SUSE-SU-2016:1690 (SUSE)
SUSE-SU-2016:1937 (SUSE)
openSUSE-SU-2016:1641 (SUSE)
openSUSE-SU-2016:2184 (SUSE)
USN-3072-2 (UBUNTU)
USN-3071-1 (UBUNTU)
USN-3072-1 (UBUNTU)
DSA-3607 (DEBIAN)
USN-3070-3 (UBUNTU)
USN-3070-4 (UBUNTU)
91021 (BID)
USN-3070-2 (UBUNTU)
USN-3070-1 (UBUNTU)
SUSE-SU-2016:2105 (SUSE)
SUSE-SU-2016:1985 (SUSE)
USN-3071-2 (UBUNTU)
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html (CONFIRM)
1041895 (SECTRACK)
CVE: CVE-2016-5829
CVE: CVE-2016-5829
Id:
CVE-2016-5829
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5829
Comment
: Multiple heap-based buffer overflows in the hiddev_ioctl_usage function in drivers/hid/usbhid/hiddev.c in the Linux kernel through 4.6.3 allow local users to cause a denial of service or possibly have unspecified other impact via a crafted (1) HIDIOCGUSAGES or (2) HIDIOCSUSAGES ioctl call.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)
References:
https://github.com/torvalds/linux/commit/93a2001bdfd5376c3dc2158653034c20392d15c5 (CONFIRM)
[oss-security] 20160626 Re: CVE Request: Linux kernel HID: hiddev buffer overflows (MLIST)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=93a2001bdfd5376c3dc2158653034c20392d15c5 (CONFIRM)
DSA-3616 (DEBIAN)
SUSE-SU-2016:1937 (SUSE)
http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html (CONFIRM)
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html (CONFIRM)
USN-3072-2 (UBUNTU)
USN-3071-1 (UBUNTU)
SUSE-SU-2016:2175 (SUSE)
SUSE-SU-2016:2181 (SUSE)
SUSE-SU-2016:2179 (SUSE)
USN-3070-3 (UBUNTU)
USN-3070-2 (UBUNTU)
SUSE-SU-2016:2178 (SUSE)
SUSE-SU-2016:1985 (SUSE)
openSUSE-SU-2016:2184 (SUSE)
SUSE-SU-2016:2180 (SUSE)
91450 (BID)
USN-3072-1 (UBUNTU)
SUSE-SU-2016:2174 (SUSE)
USN-3070-4 (UBUNTU)
SUSE-SU-2016:2177 (SUSE)
USN-3070-1 (UBUNTU)
SUSE-SU-2016:2105 (SUSE)
SUSE-SU-2016:2018 (SUSE)
USN-3071-2 (UBUNTU)
RHSA-2016:2584 (REDHAT)
RHSA-2016:2574 (REDHAT)
RHSA-2016:2006 (REDHAT)
Content available only for registered users!
ovaldb@altx-soft.com