PT-2017-1933 · Linux+1 · Linux Kernel+1
Published
2015-06-03
·
Updated
2020-07-31
·
CVE-2016-5870
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 3.x
Description
The issue is related to the msm ipc router close function in the ipc router component, which can cause a denial of service (NULL pointer dereference) or possibly have other unspecified impacts. This can be triggered by failure of an accept system call for an AF MSM IPC socket. The vulnerability can be exploited by a local attacker to cause a denial of service or other unspecified effects.
Recommendations
For Linux kernel version 3.x, consider disabling the
msm ipc router close function as a temporary workaround until a patch is available. Restrict access to the AF MSM IPC socket to minimize the risk of exploitation. Avoid using the accept system call for AF MSM IPC sockets until the issue is resolved.Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linux Kernel