CVE-2016-3699
published 2016-10-07CVE-2016-3699: The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to…
PriorityP434high7.4CVSS 3.0
AVLACHPRNUINSUCHIHAH
EPSS
0.50%
39.3th percentile
The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended Secure Boot restrictions and execute untrusted code by appending ACPI tables to the initrd.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | — | — |
| redhat | enterprise_mrg | — | — |
| redhat | linux | — | — |
CVSS provenance
nvdv3.07.4HIGHCVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_debian7.4LOW
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: ACPI table override allowed when securelevel is enabled
vendor_redhat·2016-03-05·CVSS 7.4
CVE-2016-3699 [HIGH] CWE-358 kernel: ACPI table override allowed when securelevel is enabled
kernel: ACPI table override allowed when securelevel is enabled
The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended Secure Boot restrictions and execute untrusted code by appending ACPI tables to the initrd.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5 and 6 as the code with the flaw is not present in the products listed.
This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 7 and MRG-2. Future Linux kernel updates for the respective releases might address this issue.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - No
Debian
CVE-2016-3699: linux - The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise...
vendor_debian·2016·CVSS 7.4
CVE-2016-3699 [HIGH] CVE-2016-3699: linux - The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise...
The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended Secure Boot restrictions and execute untrusted code by appending ACPI tables to the initrd.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-pv5f-x9r7-h4c8: The Linux kernel, as used in Red Hat Enterprise Linux 7
ghsa_unreviewed·2022-05-13
CVE-2016-3699 [HIGH] GHSA-pv5f-x9r7-h4c8: The Linux kernel, as used in Red Hat Enterprise Linux 7
The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended Secure Boot restrictions and execute untrusted code by appending ACPI tables to the initrd.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2016-2574.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2584.htmlhttp://www.openwall.com/lists/oss-security/2016/09/22/4http://www.securityfocus.com/bid/93114https://bugzilla.redhat.com/show_bug.cgi?id=1329653https://github.com/mjg59/linux/commit/a4a5ed2835e8ea042868b7401dced3f517cafa76http://rhn.redhat.com/errata/RHSA-2016-2574.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2584.htmlhttp://www.openwall.com/lists/oss-security/2016/09/22/4http://www.securityfocus.com/bid/93114https://bugzilla.redhat.com/show_bug.cgi?id=1329653https://github.com/mjg59/linux/commit/a4a5ed2835e8ea042868b7401dced3f517cafa76
2016-10-07
Published