PT-2015-3272 · Linux+5 · Linux Kernel+5

Dmitry Vyukov

·

Publicado

2015-12-02

·

Atualizado

2024-04-02

·

CVE-2016-3841

CVSS v3.1

7.3

Alta

VetorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.3.3
Description The issue is related to the IPv6 stack in the Linux kernel, which mishandles options data. This can be exploited by local users to gain privileges or cause a denial of service, resulting in a system crash due to a use-after-free error. The exploitation can occur via a crafted sendmsg system call.
Recommendations For Linux kernel versions prior to 4.3.3, update to version 4.3.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the sendmsg system call to minimize the risk of exploitation.

Correção

DoS

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-2110
ALT-PU-2016-1485
BDU:2016-01939
CESA-2016_0855
CESA-2016_2574
CVE-2016-3841
RHSA-2016:0855
RHSA-2016:2574
RHSA-2016:2584
RHSA-2016:2695
RHSA-2016_0855
RHSA-2016_2574
RHSA-2016_2584
SUSE-SU-2016:2976-1
SUSE-SU-2016:3069-1
SUSE-SU-2017:0333-1
SUSE-SU-2017:0494-1
SUSE-SU-2017:1102-1
USN-3083-1
USN-3083-2

Produtos afetados

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu