PT-2016-7807 · Linux+2 · Linux Kernel+2

Spender

·

Publicado

2016-11-01

·

Atualizado

2017-01-07

·

CVE-2016-9644

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions 4.4.22 through 4.4.28
Description The issue allows local users to obtain root access on non-SMEP platforms via a crafted application, due to extended asm statements in the get user asm ex macro that are incompatible with the exception table. This problem arose from incorrect backporting of a patch to older kernels.
Recommendations For Linux kernel versions 4.4.22 through 4.4.28, consider upgrading to a version that correctly includes the necessary patch to resolve the incompatibility issue with the exception table.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-2226
CVE-2016-9644
USN-3146-1
USN-3146-2
USN-3161-4

Produtos afetados

Alt Linux
Linux Kernel
Ubuntu