UBUNTU-CVE-2016-3841
The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) via a crafted sendmsg system call.
02 / AFFECTED SOFTWARE
Affected packages
96 explicit affected versions
34 explicit affected versions
31 explicit affected versions
6 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) via a crafted sendmsg system call.
05 / REFERENCES
Further evidence
- http://source.android.com/security/bulletin/2016-08-01.html
- http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.3.3
- https://ubuntu.com/security/CVE-2016-3841
- https://ubuntu.com/security/notices/USN-3083-1
- https://ubuntu.com/security/notices/USN-3083-2
- https://www.cve.org/CVERecord?id=CVE-2016-3841