PT-2017-2031 · Freebsd · Freebsd

Dmitry Chagin

·

Published

2016-01-14

·

Updated

2018-01-30

·

CVE-2016-1881

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeBSD versions 9.3, 10.1, and 10.2
Description The issue is related to insufficient access control in the FreeBSD kernel, which can be exploited to cause a denial of service or potentially gain privileges. This can be achieved by making a specially crafted Linux compatibility layer setgroups system call.
Recommendations For versions 9.3, 10.1, and 10.2, consider restricting access to the Linux compatibility layer to minimize the risk of exploitation until a patch is available. As a temporary workaround, consider disabling the setgroups system call until a fix is provided.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-01198
CVE-2016-1881
FREEBSD-SA-16_04

Affected Products

Freebsd