PT-2016-5026 · Linux+3 · Linux Kernel+3

Marcin Kościelnicki

·

Publicado

2016-04-12

·

Atualizado

2024-03-14

·

CVE-2016-2143

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.5 on s390 platforms
Description The fork implementation in the Linux kernel mishandles the case of four page-table levels, allowing local users to cause a denial of service (system crash) or possibly have unspecified other impact via a crafted application. This issue is related to arch/s390/include/asm/mmu context.h and arch/s390/include/asm/pgalloc.h.
Recommendations For Linux kernel versions prior to 4.5 on s390 platforms, update to version 4.5 or later to resolve the issue. As a temporary workaround, consider restricting access to crafted applications that could exploit this issue until a patch is available.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2016_1539
CESA-2016_2766
CVE-2016-2143
DLA-516-1
DSA-3607-1
MGASA-2016-0225
MGASA-2016-0232
MGASA-2016-0233
RHSA-2016:1539
RHSA-2016:2766
RHSA-2016_1539
RHSA-2016_2766
SUSE-SU-2016:1019-1
SUSE-SU-2016:1203-1
SUSE-SU-2016:1672-1
SUSE-SU-2016:1690-1
SUSE-SU-2016:1707-1
SUSE-SU-2016:1764-1
SUSE-SU-2016:2074-1

Produtos afetados

Centos
Linux Kernel
Red Hat
Suse