FlawAtlas
Search the atlas
USN-3234-1 Not scored

linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities

Ralf Spenneberg discovered that the ext4 implementation in the Linux kernel did not properly validate meta block groups. An attacker with physical access could use this to specially craft an ext4 image that causes a denial of service (system crash). (CVE-2016-10208) It was discovered that the Linux kernel did not clear the setgid bit during a setxattr call on a tmpfs filesystem. A local attacker could use this to gain elevated group privileges. (CVE-2017-5551)

Exploit probability Not scored
Published March 15, 2017
Required by Not available
Last source change April 22, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:16.04:LTS linux

45 explicit affected versions

Ubuntu:16.04:LTS linux-aws

4 explicit affected versions

Ubuntu:16.04:LTS linux-gke

2 explicit affected versions

Ubuntu:16.04:LTS linux-raspi2

22 explicit affected versions

Ubuntu:16.04:LTS linux-snapdragon

19 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities USN-3234-1

Ralf Spenneberg discovered that the ext4 implementation in the Linux kernel did not properly validate meta block groups. An attacker with physical access could use this to specially craft an ext4 image that causes a denial of service (system crash). (CVE-2016-10208) It was discovered that the Linux kernel did not clear the setgid bit during a setxattr call on a tmpfs filesystem. A local attacker could use this to gain elevated group privileges. (CVE-2017-5551)

View original source

05 / REFERENCES

Further evidence