PT-2016-6322 · Linux+3 · Linux Kernel+3

Kangjie Lu

·

Publicado

2016-06-27

·

Atualizado

2017-09-19

·

CVE-2016-5243

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.6.4
Description The issue is related to the tipc nl compat link dump function in net/tipc/netlink compat.c, which does not properly copy a certain string. This allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.
Recommendations For Linux kernel versions prior to 4.6.4, update to version 4.6.4 or later to resolve the issue. As a temporary workaround, consider restricting access to Netlink messages to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1774
ALT-PU-2017-1330
CVE-2016-5243
DLA-516-1
DSA-3607-1
MGASA-2016-0345
MGASA-2016-0364
SUSE-SU-2017:1247-1
SUSE-SU-2017:1301-1
SUSE-SU-2017:1360-1
SUSE-SU-2017:2342-1
SUSE-SU-2017:2525-1
USN-3049-1
USN-3050-1
USN-3051-1
USN-3052-1
USN-3053-1
USN-3054-1
USN-3055-1
USN-3056-1
USN-3057-1

Produtos afetados

Alt Linux
Linux Kernel
Suse
Ubuntu