Severity
7.5HIGH
EPSS
0.7%
top 27.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 2
Latest updateMay 14

Description

The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c in the Linux kernel through 4.5.2 incorrectly enables scatter/gather I/O, which allows remote attackers to obtain sensitive information from kernel memory by reading packet data.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages9 packages

Debianlinux< 4.5.2-1+3
Ubuntulinux< 3.13.0-87.133+1
Ubuntulinux-raspi2< 4.4.0-1012.16
Ubuntulinux-lts-wily< 4.2.0-38.45~14.04.1

Also affects: Ubuntu Linux 12.04, 14.04, 15.10, 16.04

🔴Vulnerability Details

11
GHSA
GHSA-7qq2-hfpc-p7pq: The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl22022-05-14
OSV
linux-raspi2 vulnerabilities2016-06-10
OSV
linux-lts-utopic vulnerabilities2016-06-10
OSV
linux-lts-vivid vulnerabilities2016-06-10
OSV
linux vulnerabilities2016-06-10

📋Vendor Advisories

12
Ubuntu
Linux kernel vulnerabilities2016-06-10
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities2016-06-10
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities2016-06-10
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities2016-06-10
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities2016-06-10

💬Community

2
Bugzilla
CVE-2016-2117 kernel: Kernel memory leakage to ethernet frames due to buffer overflow in ethernet drivers [fedora-all]2016-03-16
Bugzilla
CVE-2016-2117 kernel: Kernel memory leakage to ethernet frames due to buffer overflow in ethernet drivers2016-02-26
CVE-2016-2117 (HIGH CVSS 7.5) | The atl2_probe function in drivers/ | cvebase.io