PT-2017-1933 · Linux+1 · Linux Kernel+1
Publicado
2015-06-03
·
Atualizado
2020-07-31
·
CVE-2016-5870
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 3.x
Description
The issue is related to the msm ipc router close function in the ipc router component, which can cause a denial of service (NULL pointer dereference) or possibly have other unspecified impacts. This can be triggered by failure of an accept system call for an AF MSM IPC socket. The vulnerability can be exploited by a local attacker to cause a denial of service or other unspecified effects.
Recommendations
For Linux kernel version 3.x, consider disabling the
msm ipc router close function as a temporary workaround until a patch is available. Restrict access to the AF MSM IPC socket to minimize the risk of exploitation. Avoid using the accept system call for AF MSM IPC sockets until the issue is resolved.Correção
DoS
NULL Pointer Dereference
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Linux Kernel