cbcvebase.
CVE-2016-3707
published 2016-06-27

CVE-2016-3707: The icmp_check_sysrq function in net/ipv4/icmp.c in the kernel.org projects/rt patches for the Linux kernel, as used in the kernel-rt package before…

high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
The icmp_check_sysrq function in net/ipv4/icmp.c in the kernel.org projects/rt patches for the Linux kernel, as used in the kernel-rt package before 3.10.0-327.22.1 in Red Hat Enterprise Linux for Real Time 7 and other products, allows remote attackers to execute SysRq commands via crafted ICMP Echo Request packets, as demonstrated by a brute-force attack to discover a cookie, or an attack that occurs after reading the local icmp_echo_sysrq file.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.15~rc5-1~exp1 (bookworm)linux 3.15~rc5-1~exp1 (bookworm)
linuxlinux_kernel>= 0 < 3.15~rc5-1~exp13.15~rc5-1~exp1
linuxlinux_kernel>= 0 < 3.15~rc5-1~exp13.15~rc5-1~exp1
linuxlinux_kernel>= 0 < 3.15~rc5-1~exp13.15~rc5-1~exp1
linuxlinux_kernel>= 0 < 3.15~rc5-1~exp13.15~rc5-1~exp1
linuxlinux_kernel-rt<= 3.10.0
novellsuse_linux_enterprise_real_time_extension
redhatenterprise_linux_for_real_time
redhatenterprise_linux_for_real_time_for_nfv

CVSS provenance

nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH