UBUNTU-CVE-2016-4951
The tipc_nl_publ_dump function in net/tipc/socket.c in the Linux kernel through 4.6 does not verify socket existence, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a dumpit operation.
02 / AFFECTED SOFTWARE
Affected packages
27 explicit affected versions
14 explicit affected versions
8 explicit affected versions
27 explicit affected versions
9 explicit affected versions
4 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The tipc_nl_publ_dump function in net/tipc/socket.c in the Linux kernel through 4.6 does not verify socket existence, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a dumpit operation.
05 / REFERENCES
Further evidence
- http://lists.openwall.net/netdev/2016/05/14/28
- http://www.openwall.com/lists/oss-security/2016/05/21/2
- https://ubuntu.com/security/CVE-2016-4951
- https://ubuntu.com/security/notices/USN-3016-1
- https://ubuntu.com/security/notices/USN-3016-2
- https://ubuntu.com/security/notices/USN-3016-3
- https://ubuntu.com/security/notices/USN-3016-4
- https://ubuntu.com/security/notices/USN-3017-1
- https://ubuntu.com/security/notices/USN-3017-2
- https://ubuntu.com/security/notices/USN-3017-3
- https://ubuntu.com/security/notices/USN-3020-1
- https://www.cve.org/CVERecord?id=CVE-2016-4951