kernel: use-after-free via crafted IPV6 sendmsg for raw / tcp / udp / l2tp sockets.
Published Aug 6, 2016
7.3
HIGHCVSS 3.1
EPSS 0.30%
Description
The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) via a crafted sendmsg system call.
Affected products
No data.
Configuration 2
- < 3.2.75
- ≥ 3.3 · < 3.12.52
- ≥ 3.13 · < 3.16.35
- ≥ 3.17 · < 3.18.25
- ≥ 3.19 · < 4.1.15
- ≥ 4.2 · < 4.2.8
- ≥ 4.3 · < 4.3.3
No data.
Red Hat Enterprise Linux 6
kernel-0:2.6.32-642.el6
Fixed · RHSA-2016:0855
Red Hat Enterprise Linux 7
kernel-0:3.10.0-514.el7
Fixed · RHSA-2016:2574
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-514.rt56.420.el7
Fixed · RHSA-2016:2584
Red Hat Enterprise Linux 7.2 Extended Update Support
kernel-0:3.10.0-327.41.3.el7
Fixed · RHSA-2016:2695
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise MRG 2
realtime-kernel
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-642.el6 | Fixed | RHSA-2016:0855 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-514.el7 | Fixed | RHSA-2016:2574 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-514.rt56.420.el7 | Fixed | RHSA-2016:2584 |
| Red Hat Enterprise Linux 7.2 Extended Update Support | kernel-0:3.10.0-327.41.3.el7 | Fixed | RHSA-2016:2695 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise MRG 2 | realtime-kernel | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects Red Hat Enterprise Linux 6 and 7 kernels. This issue was fixed in a version 6 prior to this issue being raised. As this issue is rated as important, it has been scheduled to be fixed in a future version of Red Hat Enterprise Linux 7.
References (13)
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=45f6fad84cc305103b28d73482b344d7f5b76f39 x_refsource_CONFIRMIssue TrackingPatch
- http://rhn.redhat.com/errata/RHSA-2016-0855.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2574.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2584.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2695.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://source.android.com/security/bulletin/2016-08-01.html x_refsource_CONFIRMVendor Advisory
- http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.3.3 x_refsource_CONFIRMRelease Notes
- http://www.securityfocus.com/bid/92227 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2016-3841 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1364971 Issue Tracking
- https://github.com/torvalds/linux/commit/45f6fad84cc305103b28d73482b344d7f5b76f39 x_refsource_CONFIRMIssue TrackingPatch
- https://nvd.nist.gov/vuln/detail/CVE-2016-3841
- https://www.cve.org/CVERecord?id=CVE-2016-3841
Change history (0)
No recorded changes yet.