PT-2016-5648 · Linux+5 · Linux Kernel+5
Hector Marco
+1
·
Published
2016-04-27
·
Updated
2023-09-12
·
CVE-2016-3672
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions through 4.5.2
Description
The issue concerns the arch pick mmap layout function in the Linux kernel, which fails to properly randomize the legacy base address. This makes it easier for local users to bypass the ASLR protection mechanism for a setuid or setgid program by disabling stack-consumption resource limits, thus defeating the intended restrictions on the ADDR NO RANDOMIZE flag.
Recommendations
For Linux kernel versions through 4.5.2, update to a version that includes a fix for this issue to ensure proper randomization of the legacy base address and maintain the effectiveness of the ASLR protection mechanism.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu