UBUNTU-CVE-2016-5828
The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, which allows local users to cause a denial of service (invalid process state or TM Bad Thing exception, and system crash) or possibly have unspecified other impact by starting and suspending a transaction before an exec system call.
02 / AFFECTED SOFTWARE
Affected packages
95 explicit affected versions
30 explicit affected versions
11 explicit affected versions
30 explicit affected versions
12 explicit affected versions
7 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, which allows local users to cause a denial of service (invalid process state or TM Bad Thing exception, and system crash) or possibly have unspecified other impact by starting and suspending a transaction before an exec system call.
05 / REFERENCES
Further evidence
- https://patchwork.ozlabs.org/patch/636776/
- https://ubuntu.com/security/CVE-2016-5828
- https://ubuntu.com/security/notices/USN-3070-1
- https://ubuntu.com/security/notices/USN-3070-2
- https://ubuntu.com/security/notices/USN-3070-3
- https://ubuntu.com/security/notices/USN-3070-4
- https://ubuntu.com/security/notices/USN-3071-1
- https://ubuntu.com/security/notices/USN-3071-2
- https://www.cve.org/CVERecord?id=CVE-2016-5828