UBUNTU-CVE-2016-2085
The evm_verify_hmac function in security/integrity/evm/evm_main.c in the Linux kernel before 4.5 does not properly copy data, which makes it easier for local users to forge MAC values via a timing side-channel attack.
02 / AFFECTED SOFTWARE
Affected packages
87 explicit affected versions
38 explicit affected versions
23 explicit affected versions
10 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The evm_verify_hmac function in security/integrity/evm/evm_main.c in the Linux kernel before 4.5 does not properly copy data, which makes it easier for local users to forge MAC values via a timing side-channel attack.
05 / REFERENCES
Further evidence
- https://ubuntu.com/security/CVE-2016-2085
- https://ubuntu.com/security/notices/USN-2946-1
- https://ubuntu.com/security/notices/USN-2946-2
- https://ubuntu.com/security/notices/USN-2947-1
- https://ubuntu.com/security/notices/USN-2947-2
- https://ubuntu.com/security/notices/USN-2947-3
- https://ubuntu.com/security/notices/USN-2948-1
- https://ubuntu.com/security/notices/USN-2949-1
- https://www.cve.org/CVERecord?id=CVE-2016-2085