CVE-2016-2383
published 2016-04-27CVE-2016-2383: The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the backward-jump case, which allows local…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.37%
30.1th percentile
The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the backward-jump case, which allows local users to obtain sensitive information from kernel memory by creating a packet filter and then loading crafted BPF instructions.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 4.4.2-1 (bookworm) | linux 4.4.2-1 (bookworm) |
| linux | linux_kernel | < 4.5.0 | 4.5.0 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 4.4.2-1 | 4.4.2-1 |
| linux | linux_kernel | >= 0 < 4.4.2-1 | 4.4.2-1 |
| linux | linux_kernel | >= 0 < 4.4.2-1 | 4.4.2-1 |
| linux | linux_kernel | >= 0 < 4.4.2-1 | 4.4.2-1 |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Wily HWE) vulnerabilities
vendor_ubuntu·2016-04-06·CVSS 4.9
CVE-2015-7833 [MEDIUM] Linux kernel (Wily HWE) vulnerabilities
Title: Linux kernel (Wily HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ralf Spenneberg discovered that the usbvision driver in the Linux kernel
did not properly validate the interfaces and endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7833)
Venkatesh Pottem discovered a use-after-free vulnerability in the Linux
kernel's CXGB3 driver. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2015-8812)
Xiaofei Rex Guo discovered a timing side channel vulnerability in the Linux
Extended Verification Module (EVM). An attacker could use this to affect
system integrity. (CVE-2016-2085)
It was discovered that the extende
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-04-06·CVSS 4.9
CVE-2015-7833 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ralf Spenneberg discovered that the usbvision driver in the Linux kernel
did not properly validate the interfaces and endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7833)
Venkatesh Pottem discovered a use-after-free vulnerability in the Linux
kernel's CXGB3 driver. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2015-8812)
Xiaofei Rex Guo discovered a timing side channel vulnerability in the Linux
Extended Verification Module (EVM). An attacker could use this to affect
system integrity. (CVE-2016-2085)
It was discovered that the extended Berkeley
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2016-04-06·CVSS 4.9
CVE-2015-7833 [MEDIUM] Linux kernel (Raspberry Pi 2) vulnerabilities
Title: Linux kernel (Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ralf Spenneberg discovered that the usbvision driver in the Linux kernel
did not properly validate the interfaces and endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7833)
Venkatesh Pottem discovered a use-after-free vulnerability in the Linux
kernel's CXGB3 driver. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2015-8812)
Xiaofei Rex Guo discovered a timing side channel vulnerability in the Linux
Extended Verification Module (EVM). An attacker could use this to affect
system integrity. (CVE-2016-2085)
It was discovered that the e
Red Hat
kernel: incorrect branch fixups for eBPG allow arbitrary read
vendor_redhat·2016-02-14·CVSS 5.5
CVE-2016-2383 [MEDIUM] CWE-125 kernel: incorrect branch fixups for eBPG allow arbitrary read
kernel: incorrect branch fixups for eBPG allow arbitrary read
The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the backward-jump case, which allows local users to obtain sensitive information from kernel memory by creating a packet filter and then loading crafted BPF instructions.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6, 7 and MRG-2, as the code with the flaw is not present in the products listed.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: rea
Debian
CVE-2016-2383: linux - The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before...
vendor_debian·2016·CVSS 5.5
CVE-2016-2383 [MEDIUM] CVE-2016-2383: linux - The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before...
The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the backward-jump case, which allows local users to obtain sensitive information from kernel memory by creating a packet filter and then loading crafted BPF instructions.
Scope: local
bookworm: resolved (fixed in 4.4.2-1)
bullseye: resolved (fixed in 4.4.2-1)
forky: resolved (fixed in 4.4.2-1)
sid: resolved (fixed in 4.4.2-1)
trixie: resolved (fixed in 4.4.2-1)
GHSA
GHSA-64fh-798g-3h53: The adjust_branches function in kernel/bpf/verifier
ghsa_unreviewed·2022-05-13
CVE-2016-2383 [MEDIUM] GHSA-64fh-798g-3h53: The adjust_branches function in kernel/bpf/verifier
The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the backward-jump case, which allows local users to obtain sensitive information from kernel memory by creating a packet filter and then loading crafted BPF instructions.
OSV
CVE-2016-2383: The adjust_branches function in kernel/bpf/verifier
osv·2016-04-27·CVSS 5.5
CVE-2016-2383 [MEDIUM] CVE-2016-2383: The adjust_branches function in kernel/bpf/verifier
The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the backward-jump case, which allows local users to obtain sensitive information from kernel memory by creating a packet filter and then loading crafted BPF instructions.
OSV
linux-lts-wily vulnerabilities
osv·2016-04-06·CVSS 4.9
CVE-2015-7833 [MEDIUM] linux-lts-wily vulnerabilities
linux-lts-wily vulnerabilities
Ralf Spenneberg discovered that the usbvision driver in the Linux kernel
did not properly validate the interfaces and endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7833)
Venkatesh Pottem discovered a use-after-free vulnerability in the Linux
kernel's CXGB3 driver. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2015-8812)
Xiaofei Rex Guo discovered a timing side channel vulnerability in the Linux
Extended Verification Module (EVM). An attacker could use this to affect
system integrity. (CVE-2016-2085)
It was discovered that the extended Berkeley Packet Filter (eBPF)
implementation in the Linux kernel did not c
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2383 kernel: incorrect branch fixups for eBPG allow arbitrary read
bugzilla·2016-02-15·CVSS 5.5
CVE-2016-2383 [MEDIUM] CVE-2016-2383 kernel: incorrect branch fixups for eBPG allow arbitrary read
CVE-2016-2383 kernel: incorrect branch fixups for eBPG allow arbitrary read
When ctx access is used, the kernel often needs to expand/rewrite
instructions, so after that patching, branch offsets have to be
adjusted for both forward and backward jumps in the new eBPF program,
but for backward jumps it fails to account the delta. Meaning, for
example, if the expansion happens exactly on the insn that sits at
the jump target, it doesn't fix up the back jump offset.
Upstream report and fix:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a1b14d27ed0965838350f1377ff97c93ee383492
External reference:
http://seclists.org/oss-sec/2016/q1/330
CVE assignment:
http://seclists.org/oss-sec/2016/q1/333
Discussion:
Created kernel tracking bugs for this issue:
Affects:
Bugzilla
CVE-2016-2383 kernel: incorrect branch fixups for eBPG allow arbitrary read [fedora-all]
bugzilla·2016-02-15·CVSS 5.5
CVE-2016-2383 [MEDIUM] CVE-2016-2383 kernel: incorrect branch fixups for eBPG allow arbitrary read [fedora-all]
CVE-2016-2383 kernel: incorrect branch fixups for eBPG allow arbitrary read [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
arXiv
B-Side: Binary-Level Static System Call Identification
arxiv_fulltext·2024-10-23
B-Side: Binary-Level Static System Call Identification
none
20242024
[MIDDLEWARE '24]24th International Middleware ConferenceDecember 2--6, 2024Hong Kong, Hong Kong
24th International Middleware Conference (MIDDLEWARE '24), December 2--6, 2024, Hong Kong, Hong Kong
10.1145/3652892.3700761
979-8-4007-0623-3/24/12
: Binary-Level Static System Call Identification
Gaspard Thévenon
ENS Lyon
Lyon
France
Kevin Nguetchouang
Grenoble INP
Grenoble
France
Kahina Lazri
Orange Innovation
Paris
France
Alain Tchana
Grenoble INP
Grenoble
France
| Pierre Olivier
The University of Manchester
Manchester
United Kingdom
## Abstract
System call filtering is widely used to secure programs in multi-tenant environments, and to sandbox applications in modern desktop software deployment and package management systems.
Filtering rules are hard to write and m
CTF
bpf_badjmp / README
ctf_writeups·2021·CVSS 5.5
CVE-2016-2383 [MEDIUM] bpf_badjmp / README
# UIUCTF 2021: ebpf_badjmp solution
Decription:
>We recreated CVE-2016-2383. Your task is to read out the variable named `uiuctf_flag` in the kernel memory, by building an arbitrary kernel memory read via a malicious eBPF program. Use of provided starter code is optional; if you have better methods feel free to use them instead.
>
>`$ stty raw -echo; nc bpf-badjmp.chal.uiuc.tf 1337; stty -raw echo`
>
>Upload large files to VM: `$ nc bpf-badjmp.chal.uiuc.tf 1338
>HINT: How do you create a backwards jump without introducing unreachable code or creating loops?
## The Vulnerability
Here we're given the patch which will introduce bug in eBPF kernel subsystem.
``` diff
diff --git a/kernel/bpf/core.c b/kernel/bpf/core.c
index 75244ecb2389..277f0e475181 100644
--- a/kernel/bpf/core.c
+++ b/kerne
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a1b14d27ed0965838350f1377ff97c93ee383492http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.htmlhttp://www.openwall.com/lists/oss-security/2016/02/14/1http://www.ubuntu.com/usn/USN-2947-1http://www.ubuntu.com/usn/USN-2947-2http://www.ubuntu.com/usn/USN-2947-3https://bugzilla.redhat.com/show_bug.cgi?id=1308452https://github.com/torvalds/linux/commit/a1b14d27ed0965838350f1377ff97c93ee383492http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a1b14d27ed0965838350f1377ff97c93ee383492http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.htmlhttp://www.openwall.com/lists/oss-security/2016/02/14/1http://www.ubuntu.com/usn/USN-2947-1http://www.ubuntu.com/usn/USN-2947-2http://www.ubuntu.com/usn/USN-2947-3https://bugzilla.redhat.com/show_bug.cgi?id=1308452https://github.com/torvalds/linux/commit/a1b14d27ed0965838350f1377ff97c93ee383492
2016-04-27
Published