PT-2015-3272 · Linux+5 · Linux Kernel+5

Dmitry Vyukov

·

Published

2015-12-02

·

Updated

2024-04-02

·

CVE-2016-3841

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.3.3
Description The issue is related to the IPv6 stack in the Linux kernel, which mishandles options data. This can be exploited by local users to gain privileges or cause a denial of service, resulting in a system crash due to a use-after-free error. The exploitation can occur via a crafted sendmsg system call.
Recommendations For Linux kernel versions prior to 4.3.3, update to version 4.3.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the sendmsg system call to minimize the risk of exploitation.

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-2110
ALT-PU-2016-1485
BDU:2016-01939
CESA-2016_0855
CESA-2016_2574
CVE-2016-3841
RHSA-2016:0855
RHSA-2016:2574
RHSA-2016:2584
RHSA-2016:2695
RHSA-2016_0855
RHSA-2016_2574
RHSA-2016_2584
SUSE-SU-2016:2976-1
SUSE-SU-2016:3069-1
SUSE-SU-2017:0333-1
SUSE-SU-2017:0494-1
SUSE-SU-2017:1102-1
USN-3083-1
USN-3083-2

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu