UBUNTU-CVE-2016-9644
The __get_user_asm_ex macro in arch/x86/include/asm/uaccess.h in the Linux kernel 4.4.22 through 4.4.28 contains extended asm statements that are incompatible with the exception table, which allows local users to obtain root access on non-SMEP platforms via a crafted application. NOTE: this vulnerability exists because of incorrect backporting of the CVE-2016-9178 patch to older kernels.
02 / AFFECTED SOFTWARE
Affected packages
129 explicit affected versions
16 explicit affected versions
36 explicit affected versions
13 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The __get_user_asm_ex macro in arch/x86/include/asm/uaccess.h in the Linux kernel 4.4.22 through 4.4.28 contains extended asm statements that are incompatible with the exception table, which allows local users to obtain root access on non-SMEP platforms via a crafted application. NOTE: this vulnerability exists because of incorrect backporting of the CVE-2016-9178 patch to older kernels.
05 / REFERENCES
Further evidence
- http://www.openwall.com/lists/oss-security/2016/11/03/2
- http://www.openwall.com/lists/oss-security/2016/11/07/4
- https://lwn.net/Articles/705220/
- https://ubuntu.com/security/CVE-2016-9644
- https://ubuntu.com/security/notices/USN-3146-1
- https://ubuntu.com/security/notices/USN-3146-2
- https://ubuntu.com/security/notices/USN-3161-4
- https://www.cve.org/CVERecord?id=CVE-2016-9644