PT-2016-5648 · Linux+5 · Linux Kernel+5

Hector Marco

+1

·

Published

2016-04-27

·

Updated

2023-09-12

·

CVE-2016-3672

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 4.5.2
Description The issue concerns the arch pick mmap layout function in the Linux kernel, which fails to properly randomize the legacy base address. This makes it easier for local users to bypass the ASLR protection mechanism for a setuid or setgid program by disabling stack-consumption resource limits, thus defeating the intended restrictions on the ADDR NO RANDOMIZE flag.
Recommendations For Linux kernel versions through 4.5.2, update to a version that includes a fix for this issue to ensure proper randomization of the legacy base address and maintain the effectiveness of the ASLR protection mechanism.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1470
ALT-PU-2017-1330
CESA-2018_1062
CVE-2016-3672
DLA-516-1
DSA-3607-1
MGASA-2016-0225
MGASA-2016-0233
OPENSUSE-SU-2016_1641-1
OPENSUSE-SU-2016_2144-1
OPENSUSE-SU-2016_2184-1
RHSA-2018:0676
RHSA-2018:1062
RHSA-2018_0676
RHSA-2018_1062
SUSE-SU-2016:1690-1
SUSE-SU-2016:1937-1
SUSE-SU-2016:2105-1
USN-2965-1
USN-2965-2
USN-2965-3
USN-2965-4
USN-2989-1
USN-2996-1
USN-2997-1
USN-2998-1
USN-3000-1
USN-3001-1
USN-3002-1
USN-3003-1
USN-3004-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu