UBUNTU-CVE-2016-3135
Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32-bit platforms allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.
02 / AFFECTED SOFTWARE
Affected packages
9 explicit affected versions
10 explicit affected versions
29 explicit affected versions
11 explicit affected versions
6 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32-bit platforms allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.
05 / REFERENCES
Further evidence
- http://marc.info/?l=netfilter-devel&m=145757136822750&w=2
- http://www.openwall.com/lists/oss-security/2016/03/14/1
- https://code.google.com/p/google-security-research/issues/detail?id=758
- https://ubuntu.com/security/CVE-2016-3135
- https://ubuntu.com/security/notices/USN-2930-1
- https://ubuntu.com/security/notices/USN-2930-2
- https://ubuntu.com/security/notices/USN-2930-3
- https://ubuntu.com/security/notices/USN-3054-1
- https://ubuntu.com/security/notices/USN-3055-1
- https://ubuntu.com/security/notices/USN-3056-1
- https://ubuntu.com/security/notices/USN-3057-1
- https://www.cve.org/CVERecord?id=CVE-2016-3135