PT-2016-6018 · Linux+3 · Linux Kernel+3

Jann Horn

·

Published

2016-05-05

·

Updated

2024-06-15

·

CVE-2016-4557

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.5.5
Description The issue arises from the replace map fd with map ptr function in kernel/bpf/verifier.c, which fails to properly maintain an fd data structure. This allows local users to gain privileges or cause a denial of service (use-after-free) via crafted BPF instructions that reference an incorrect file descriptor.
Recommendations For Linux kernel versions prior to 4.5.5, update to version 4.5.5 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2016-1534
ALT-PU-2016-1538
CVE-2016-4557
OPENSUSE-SU-2016_1641-1
OPENSUSE-SU-2016_2290-1
OPENSUSE-SU-2024:10128-1
USN-2965-1
USN-2965-2
USN-2965-3
USN-2965-4

Affected Products

Alt Linux
Linux Kernel
Suse
Ubuntu