UBUNTU-CVE-2016-3134
The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.
02 / AFFECTED SOFTWARE
Affected packages
92 explicit affected versions
43 explicit affected versions
27 explicit affected versions
14 explicit affected versions
8 explicit affected versions
27 explicit affected versions
9 explicit affected versions
4 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.
05 / REFERENCES
Further evidence
- http://marc.info/?l=netfilter-devel&m=145757134822741&w=2
- http://www.openwall.com/lists/oss-security/2016/03/14/1
- https://code.google.com/p/google-security-research/issues/detail?id=758
- https://ubuntu.com/security/CVE-2016-3134
- https://ubuntu.com/security/notices/USN-2929-1
- https://ubuntu.com/security/notices/USN-2929-2
- https://ubuntu.com/security/notices/USN-2930-1
- https://ubuntu.com/security/notices/USN-2930-2
- https://ubuntu.com/security/notices/USN-2930-3
- https://ubuntu.com/security/notices/USN-2931-1
- https://ubuntu.com/security/notices/USN-2932-1
- https://ubuntu.com/security/notices/USN-3049-1
- https://ubuntu.com/security/notices/USN-3050-1
- https://www.cve.org/CVERecord?id=CVE-2016-3134