kernel: CXGB3: Logic bug in return code handling prematurely frees key structures causing Use after free or kernel panic.
Published Apr 27, 2016
9.8
CRITICALCVSS 3.1
EPSS 14.55%
Description
drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted packets.
Affected products
No data.
Configuration 1
Configuration 2
- < 3.2.78
- ≥ 3.3 · < 3.10.99
- ≥ 3.11 · < 3.12.56
- ≥ 3.13 · < 3.14.63
- ≥ 3.15 · < 3.16.35
- ≥ 3.17 · < 3.18.31
- ≥ 3.19 · < 4.1.22
- ≥ 4.2.0 · < 4.4.4
Configuration 3
- 12.04
- 14.04
- 15.10
No data.
Red Hat Enterprise Linux 7
kernel-0:3.10.0-514.el7
Fixed · RHSA-2016:2574
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-514.rt56.420.el7
Fixed · RHSA-2016:2584
Red Hat Enterprise Linux 5
kernel
Will not fix
Red Hat Enterprise Linux 6
kernel
Will not fix
Red Hat Enterprise MRG 2
kernel
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-514.el7 | Fixed | RHSA-2016:2574 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-514.rt56.420.el7 | Fixed | RHSA-2016:2584 |
| Red Hat Enterprise Linux 5 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | kernel | Will not fix | n/a |
| Red Hat Enterprise MRG 2 | kernel | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the Linux kernels as shipped with Red Hat Enterprise Linux 5, 6 and 7 and Red Hat Enterprise MRG 2 and realtime kernels and may be addressed in a future update. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates in Red Hat Enterprise Linux 5 and 6 . For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
References (39)
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=67f1aee6f45059fd6b0f5b0ecb2c97ad0451f6b3 x_refsource_CONFIRMVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00019.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00025.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00026.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00027.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00028.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00029.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00030.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00031.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00032.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00033.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00034.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00036.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00037.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2574.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2584.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.debian.org/security/2016/dsa-3503 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/02/11/1 mailing-listx_refsource_MLISTMailing ListRelease NotesThird Party Advisory
- http://www.securityfocus.com/bid/83218 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-2946-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2946-2 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2947-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2947-2 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2947-3 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2948-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2948-2 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2949-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2967-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2967-2 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2015-8812 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1303532 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://github.com/torvalds/linux/commit/67f1aee6f45059fd6b0f5b0ecb2c97ad0451f6b3 x_refsource_CONFIRMPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2015-8812
- https://www.cve.org/CVERecord?id=CVE-2015-8812
Change history (0)
No recorded changes yet.