Back

MEDIUM

kernel: netfilter: nfnetlink: correctly validate length of batch messages

Published Nov 16, 2016

Description

The nfnetlink_rcv_batch function in net/netfilter/nfnetlink.c in the Linux kernel before 4.5 does not check whether a batch message's length field is large enough, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (infinite loop or out-of-bounds read) by leveraging the CAP_NET_ADMIN capability.

Affected products

Remediation

Red Hat statement

This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG-2 as code with the flaw is not present in the products listed.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner google_android
Published Nov 16, 2016
Updated Aug 6, 2024
Reserved Sep 9, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Feb 2, 2016