PT-2016-3185 · Linux+2 · Linux Kernel+2
Ben Hawkes
·
Publicado
2016-03-09
·
Atualizado
2024-06-15
·
CVE-2016-3135
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 4.5.2
Description
The issue is caused by an integer overflow in the
xt alloc table info function in net/netfilter/x tables.c of the Linux kernel. This can be exploited by a local attacker to gain privileges or cause a denial of service, resulting in heap memory corruption. The exploitation occurs via an IPT SO SET REPLACE setsockopt call.Recommendations
For Linux kernel versions prior to 4.5.2, update to a version 4.5.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the
setsockopt call with the IPT SO SET REPLACE option to minimize the risk of exploitation.Exploit
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Linux Kernel
Ubuntu