CVE-2016-10200
published 2017-03-07CVE-2016-10200: Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4.8.14 allows local users to gain privileges or cause a denial of service…
PriorityP431high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.30%
21.9th percentile
Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4.8.14 allows local users to gain privileges or cause a denial of service (use-after-free) by making multiple bind system calls without properly ascertaining whether a socket has the SOCK_ZAPPED status, related to net/l2tp/l2tp_ip.c and net/l2tp/l2tp_ip6.c.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.8.15-1 (bookworm) | linux 4.8.15-1 (bookworm) |
| android | <= 7.1.1 | — | |
| android | — | — | |
| linux | linux_kernel | >= 0 < 4.8.15-1 | 4.8.15-1 |
| linux | linux_kernel | >= 0 < 4.8.15-1 | 4.8.15-1 |
| linux | linux_kernel | >= 0 < 4.8.15-1 | 4.8.15-1 |
| linux | linux_kernel | >= 0 < 4.8.15-1 | 4.8.15-1 |
| linux | linux_kernel | >= 0 < 3.13.0-132.181 | 3.13.0-132.181 |
| linux | linux_kernel | >= 3.0.34 < 3.2 | 3.2 |
| linux | linux_kernel | >= 3.13 < 3.16.40 | 3.16.40 |
| linux | linux_kernel | >= 3.17 < 3.18.52 | 3.18.52 |
| linux | linux_kernel | >= 3.19 < 4.4.38 | 4.4.38 |
| linux | linux_kernel | >= 3.2.20 < 3.2.88 | 3.2.88 |
| linux | linux_kernel | >= 3.4.2 < 3.12.69 | 3.12.69 |
| linux | linux_kernel | >= 4.5 < 4.8.14 | 4.8.14 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-09-18·CVSS 7.8
CVE-2016-10044 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a buffer overflow existed in the Bluetooth stack of
the Linux kernel when handling L2CAP configuration responses. A physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-2017-1000251)
It was discovered that the asynchronous I/O (aio) subsystem of the Linux
kernel did not properly set permissions on aio memory mappings in some
situations. An attacker could use this to more easily exploit other
vulnerabilities. (CVE-2016-10044)
Baozeng Ding and Andrey Konovalov discovered a race condition in the L2TPv3
IP Encapsulation implementation in the Linux kernel. A local attacker could
use this to cause a denial of service (system cra
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2017-09-18·CVSS 7.8
CVE-2016-10044 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3422-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 LTS.
It was discovered that a buffer overflow existed in the Bluetooth stack of
the Linux kernel when handling L2CAP configuration responses. A physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-2017-1000251)
It was discovered that the asynchronous I/O (aio) subsystem of the Linux
kernel did not properly set permissions on aio memory mappings in some
situations. An attacker could use this to more easily exploit other
vulnerabi
Android
CVE-2016-10200: Android Security Bulletin 2017-03-01
CVE: CVE-2016-10200
Severity: CRITICAL
References: A-33753815
Upstream kernel
vendor_android·2017-03-01·CVSS 7.0
CVE-2016-10200 [HIGH] CVE-2016-10200: Android Security Bulletin 2017-03-01
CVE: CVE-2016-10200
Severity: CRITICAL
References: A-33753815
Upstream kernel
Android Security Bulletin 2017-03-01
CVE: CVE-2016-10200
Severity: CRITICAL
References: A-33753815
Upstream kernel
Red Hat
kernel: l2tp: Race condition in the L2TPv3 IP encapsulation feature
vendor_redhat·2016-11-18·CVSS 7.0
CVE-2016-10200 [HIGH] CWE-362 kernel: l2tp: Race condition in the L2TPv3 IP encapsulation feature
kernel: l2tp: Race condition in the L2TPv3 IP encapsulation feature
Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4.8.14 allows local users to gain privileges or cause a denial of service (use-after-free) by making multiple bind system calls without properly ascertaining whether a socket has the SOCK_ZAPPED status, related to net/l2tp/l2tp_ip.c and net/l2tp/l2tp_ip6.c.
A use-after-free flaw was found in the Linux kernel which enables a race condition in the L2TPv3 IP Encapsulation feature. A local user could use this flaw to escalate their privileges or crash the system.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5 and 6 as the code with the flaw is not present in the products listed.
This i
Debian
CVE-2016-10200: linux - Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before...
vendor_debian·2016·CVSS 7.0
CVE-2016-10200 [HIGH] CVE-2016-10200: linux - Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before...
Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4.8.14 allows local users to gain privileges or cause a denial of service (use-after-free) by making multiple bind system calls without properly ascertaining whether a socket has the SOCK_ZAPPED status, related to net/l2tp/l2tp_ip.c and net/l2tp/l2tp_ip6.c.
Scope: local
bookworm: resolved (fixed in 4.8.15-1)
bullseye: resolved (fixed in 4.8.15-1)
forky: resolved (fixed in 4.8.15-1)
sid: resolved (fixed in 4.8.15-1)
trixie: resolved (fixed in 4.8.15-1)
GHSA
GHSA-w7wm-xr7c-fp79: Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4
ghsa_unreviewed·2022-05-14
CVE-2016-10200 [HIGH] GHSA-w7wm-xr7c-fp79: Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4
Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4.8.14 allows local users to gain privileges or cause a denial of service (use-after-free) by making multiple bind system calls without properly ascertaining whether a socket has the SOCK_ZAPPED status, related to net/l2tp/l2tp_ip.c and net/l2tp/l2tp_ip6.c.
OSV
linux vulnerabilities
osv·2017-09-18·CVSS 7.8
CVE-2017-1000251 [HIGH] linux vulnerabilities
linux vulnerabilities
It was discovered that a buffer overflow existed in the Bluetooth stack of
the Linux kernel when handling L2CAP configuration responses. A physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-2017-1000251)
It was discovered that the asynchronous I/O (aio) subsystem of the Linux
kernel did not properly set permissions on aio memory mappings in some
situations. An attacker could use this to more easily exploit other
vulnerabilities. (CVE-2016-10044)
Baozeng Ding and Andrey Konovalov discovered a race condition in the L2TPv3
IP Encapsulation implementation in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2016-10200)
Andreas Gruenbacher an
OSV
CVE-2016-10200: Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4
osv·2017-03-07·CVSS 7.0
CVE-2016-10200 [HIGH] CVE-2016-10200: Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4
Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4.8.14 allows local users to gain privileges or cause a denial of service (use-after-free) by making multiple bind system calls without properly ascertaining whether a socket has the SOCK_ZAPPED status, related to net/l2tp/l2tp_ip.c and net/l2tp/l2tp_ip6.c.
No detection rules found.
arXiv
A Context-Sensitive, Outlier-Based Static Analysis to Find Kernel Race Conditions
arxiv_fulltext·2024-03-30
A Context-Sensitive, Outlier-Based Static Analysis to Find Kernel Race Conditions
A Context-Sensitive, Outlier-Based Static Analysis to Find Kernel Race Conditions
Niels Dossche
Ghent University
Bert Abrath
Ghent University
Bart Coppens
Ghent University
* [1][1ex]
-0.5ex 0.5ex 0 0
* [1][1ex]
-0.5ex 0.5ex 0 0
* [1][1ex]
0 0.5ex 0 0
* [1][1ex]
* [1][1ex]
* [1][1ex]
1mm
bccnt
[1]bccnt
magentaBart [ ]: #1
bacnt
[1]bacnt
blueBert [ ]: #1
ndcnt
carrotorangergb0.93, 0.57, 0.13
[1]ndcnt
carrotorangeNiels [ ]: #1
LLIF
[1]round(#1, 2) (floor(100*#1) == 100*#1) ? 0 : 9 0.00
[2]
#1#2
[1]100 * #1falsepositives / (#1truepositives + #1falsepositives)%
1214
24
23
1107
211
648
248
modulesandcorenoheuristics
611
257
169
185
modulesandcoreallheuristics
0.10%
1 minute and 3 seconds
56 seconds
49 seconds
8 minutes and 59 seconds
5 minutes and 42 seconds
mygreenrgb0,
arXiv
Timeloops: Automatic System Call Policy Learning for Containerized Microservices
arxiv_fulltext·2022-09-26
Timeloops: Automatic System Call Policy Learning for Containerized Microservices
Meghna Pancholi
[email protected]
Columbia University
Andreas D. Kellas
[email protected]
Columbia University
Vasileios P. Kemerlis
[email protected]
Brown University
Simha Sethumadhavan
[email protected]
Columbia University
## Abstract
We introduce , a novel technique for automatically learning system
call filtering policies for containerized microservices applications. At
run-time, automatically learns which system calls a program should
be allowed to invoke, while rejecting attempts to call spurious system calls.
Further, addresses many of the shortcomings of state-of-the-art
static analysis-based techniques, such as the ability to generate tight filters
for programs written in interpreted languages such as PHP, Python, and
JavaScript. has a simple and rob
Bugzilla
CVE-2016-10200 kernel: l2tp: Race condition in the L2TPv3 IP encapsulation feature
bugzilla·2017-03-08·CVSS 7.0
CVE-2016-10200 [HIGH] CVE-2016-10200 kernel: l2tp: Race condition in the L2TPv3 IP encapsulation feature
CVE-2016-10200 kernel: l2tp: Race condition in the L2TPv3 IP encapsulation feature
A flaw was found on the linux kernel which enables a race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4.8.14 allows local users to gain privileges or cause a denial of service (use-after-free) by making multiple bind system calls without properly ascertaining whether a socket has the SOCK_ZAPPED status, related to net/l2tp/l2tp_ip.c and net/l2tp/l2tp_ip6.c.
Upstream patch:
https://github.com/torvalds/linux/commit/32c231164b76
Follow-up upstream patches:
https://github.com/torvalds/linux/commit/0382a25af3c7
https://github.com/torvalds/linux/commit/a3c18422a4b4
https://github.com/torvalds/linux/commit/d5e3a190937a
https://github.com/torvalds/linux/commit/df90e6886146
https:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=32c231164b762dddefa13af5a0101032c70b50efhttp://source.android.com/security/bulletin/2017-03-01.htmlhttp://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.8.14http://www.securityfocus.com/bid/101783http://www.securitytracker.com/id/1037965http://www.securitytracker.com/id/1037968https://access.redhat.com/errata/RHSA-2017:1842https://access.redhat.com/errata/RHSA-2017:2077https://access.redhat.com/errata/RHSA-2017:2437https://access.redhat.com/errata/RHSA-2017:2444https://github.com/torvalds/linux/commit/32c231164b762dddefa13af5a0101032c70b50efhttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=32c231164b762dddefa13af5a0101032c70b50efhttp://source.android.com/security/bulletin/2017-03-01.htmlhttp://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.8.14http://www.securityfocus.com/bid/101783http://www.securitytracker.com/id/1037965http://www.securitytracker.com/id/1037968https://access.redhat.com/errata/RHSA-2017:1842https://access.redhat.com/errata/RHSA-2017:2077https://access.redhat.com/errata/RHSA-2017:2437https://access.redhat.com/errata/RHSA-2017:2444https://github.com/torvalds/linux/commit/32c231164b762dddefa13af5a0101032c70b50ef
2017-03-07
Published