PT-2016-5648 · Linux+5 · Linux Kernel+5

Hector Marco

+1

·

Publicado

2016-04-27

·

Atualizado

2023-09-12

·

CVE-2016-3672

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 4.5.2
Description The issue concerns the arch pick mmap layout function in the Linux kernel, which fails to properly randomize the legacy base address. This makes it easier for local users to bypass the ASLR protection mechanism for a setuid or setgid program by disabling stack-consumption resource limits, thus defeating the intended restrictions on the ADDR NO RANDOMIZE flag.
Recommendations For Linux kernel versions through 4.5.2, update to a version that includes a fix for this issue to ensure proper randomization of the legacy base address and maintain the effectiveness of the ASLR protection mechanism.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1470
ALT-PU-2017-1330
CESA-2018_1062
CVE-2016-3672
DLA-516-1
DSA-3607-1
MGASA-2016-0225
MGASA-2016-0233
OPENSUSE-SU-2016_1641-1
OPENSUSE-SU-2016_2144-1
OPENSUSE-SU-2016_2184-1
RHSA-2018:0676
RHSA-2018:1062
RHSA-2018_0676
RHSA-2018_1062
SUSE-SU-2016:1690-1
SUSE-SU-2016:1937-1
SUSE-SU-2016:2105-1
USN-2965-1
USN-2965-2
USN-2965-3
USN-2965-4
USN-2989-1
USN-2996-1
USN-2997-1
USN-2998-1
USN-3000-1
USN-3001-1
USN-3002-1
USN-3003-1
USN-3004-1

Produtos afetados

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu