PT-2016-5021 · Linux+5 · Linux Kernel+5

Justin Yackoski

·

Published

2016-05-02

·

Updated

2023-02-12

·

CVE-2016-2117

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.5.2
Description The issue allows remote attackers to obtain sensitive information from kernel memory by reading packet data. This is due to the incorrect enabling of scatter/gather I/O in the atl2 probe function.
Recommendations For Linux kernel versions prior to 4.5.2, update to a version that contains the fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1470
ALT-PU-2017-1330
CESA-2016_2574
CVE-2016-2117
DSA-3607-1
MGASA-2016-0225
MGASA-2016-0232
MGASA-2016-0233
OPENSUSE-SU-2017_0906-1
OPENSUSE-SU-2017_0907-1
RHSA-2016:2574
RHSA-2016:2584
RHSA-2016_2574
RHSA-2016_2584
SUSE-SU-2017:1183-1
SUSE-SU-2017:1247-1
SUSE-SU-2017:1360-1
SUSE-SU-2017:1990-1
USN-2989-1
USN-2998-1
USN-3000-1
USN-3001-1
USN-3002-1
USN-3003-1
USN-3004-1
USN-3005-1
USN-3006-1
USN-3007-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu