CVE-2016-3841
published 2016-08-06CVE-2016-3841: The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which allows local users to gain privileges or cause a denial of service…
PriorityP433high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
0.30%
22.3th percentile
The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) via a crafted sendmsg system call.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.3.3-1 (bookworm) | linux 4.3.3-1 (bookworm) |
| android | — | — | |
| android | — | — | |
| linux | linux_kernel | < 3.2.75 | 3.2.75 |
| linux | linux_kernel | >= 0 < 4.3.3-1 | 4.3.3-1 |
| linux | linux_kernel | >= 0 < 4.3.3-1 | 4.3.3-1 |
| linux | linux_kernel | >= 0 < 4.3.3-1 | 4.3.3-1 |
| linux | linux_kernel | >= 0 < 4.3.3-1 | 4.3.3-1 |
| linux | linux_kernel | >= 0 < 3.13.0-96.143 | 3.13.0-96.143 |
| linux | linux_kernel | >= 3.13 < 3.16.35 | 3.16.35 |
| linux | linux_kernel | >= 3.17 < 3.18.25 | 3.18.25 |
| linux | linux_kernel | >= 3.19 < 4.1.15 | 4.1.15 |
| linux | linux_kernel | >= 3.3 < 3.12.52 | 3.12.52 |
| linux | linux_kernel | >= 4.2 < 4.2.8 | 4.2.8 |
| linux | linux_kernel | >= 4.3 < 4.3.3 | 4.3.3 |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.3HIGH
vendor_debian7.3HIGH
vendor_redhat7.3HIGH
vendor_ubuntu6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-09-19·CVSS 6.2
CVE-2015-8767 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dmitry Vyukov discovered that the IPv6 implementation in the Linux kernel
did not properly handle options data, including a use-after-free. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2016-3841)
It was discovered that a race condition existed when handling heartbeat-
timeout events in the SCTP implementation of the Linux kernel. A remote
attacker could use this to cause a denial of service. (CVE-2015-8767)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, whi
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2016-09-19·CVSS 6.2
CVE-2015-8767 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
USN-3083-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 LTS.
Dmitry Vyukov discovered that the IPv6 implementation in the Linux kernel
did not properly handle options data, including a use-after-free. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2016-3841)
It was discovered that a race condition existed when handling heartbeat-
timeout events in the SCTP implementation of the Linux kernel. A remote
attacker could use this to cause a denial of service. (CVE-201
Red Hat
kernel: use-after-free via crafted IPV6 sendmsg for raw / tcp / udp / l2tp sockets.
vendor_redhat·2016-08-08·CVSS 7.3
CVE-2016-3841 [HIGH] CWE-667 kernel: use-after-free via crafted IPV6 sendmsg for raw / tcp / udp / l2tp sockets.
kernel: use-after-free via crafted IPV6 sendmsg for raw / tcp / udp / l2tp sockets.
The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) via a crafted sendmsg system call.
It was found that the Linux kernel's IPv6 implementation mishandled socket options. A local attacker could abuse concurrent access to the socket options to escalate their privileges, or cause a denial of service (use-after-free and system crash) via a crafted sendmsg system call.
Statement: This issue affects Red Hat Enterprise Linux 6 and 7 kernels. This issue was fixed in a version 6 prior to this issue being raised.
As this issue is rated as important, it has been scheduled to be fixed in a
Android
CVE-2016-3841: Android Security Bulletin 2016-08-01
CVE: CVE-2016-3841
Severity: CRITICAL
References: A-28746669
Upstream kernel
vendor_android·2016-08-01·CVSS 7.3
CVE-2016-3841 [HIGH] CVE-2016-3841: Android Security Bulletin 2016-08-01
CVE: CVE-2016-3841
Severity: CRITICAL
References: A-28746669
Upstream kernel
Android Security Bulletin 2016-08-01
CVE: CVE-2016-3841
Severity: CRITICAL
References: A-28746669
Upstream kernel
Debian
CVE-2016-3841: linux - The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which a...
vendor_debian·2016·CVSS 7.3
CVE-2016-3841 [HIGH] CVE-2016-3841: linux - The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which a...
The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) via a crafted sendmsg system call.
Scope: local
bookworm: resolved (fixed in 4.3.3-1)
bullseye: resolved (fixed in 4.3.3-1)
forky: resolved (fixed in 4.3.3-1)
sid: resolved (fixed in 4.3.3-1)
trixie: resolved (fixed in 4.3.3-1)
GHSA
GHSA-2jwc-wqjh-543h: The IPv6 stack in the Linux kernel before 4
ghsa_unreviewed·2022-05-14
CVE-2016-3841 [HIGH] GHSA-2jwc-wqjh-543h: The IPv6 stack in the Linux kernel before 4
The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) via a crafted sendmsg system call.
OSV
linux vulnerabilities
osv·2016-09-19·CVSS 6.2
CVE-2016-3841 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Dmitry Vyukov discovered that the IPv6 implementation in the Linux kernel
did not properly handle options data, including a use-after-free. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2016-3841)
It was discovered that a race condition existed when handling heartbeat-
timeout events in the SCTP implementation of the Linux kernel. A remote
attacker could use this to cause a denial of service. (CVE-2015-8767)
OSV
CVE-2016-3841: The IPv6 stack in the Linux kernel before 4
osv·2016-08-06·CVSS 7.3
CVE-2016-3841 [HIGH] CVE-2016-3841: The IPv6 stack in the Linux kernel before 4
The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) via a crafted sendmsg system call.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3841 kernel: use-after-free via crafted sendmsg system call [fedora-all]
bugzilla·2016-08-08·CVSS 7.3
CVE-2016-3841 [HIGH] CVE-2016-3841 kernel: use-after-free via crafted sendmsg system call [fedora-all]
CVE-2016-3841 kernel: use-after-free via crafted sendmsg system call [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2016-3841 kernel: use-after-free via crafted IPV6 sendmsg for raw / tcp / udp / l2tp sockets.
bugzilla·2016-08-08·CVSS 7.3
CVE-2016-3841 [HIGH] CVE-2016-3841 kernel: use-after-free via crafted IPV6 sendmsg for raw / tcp / udp / l2tp sockets.
CVE-2016-3841 kernel: use-after-free via crafted IPV6 sendmsg for raw / tcp / udp / l2tp sockets.
It was found that the Linux kernel's IPv6 implementation mishandles socket option data. A local attacker can abuse concurrent access to the socket options to escalate their privileges, or cause a denial of service (use-after-free and system crash) via a crafted sendmsg system call.
Upstream patch:
https://github.com/torvalds/linux/commit/45f6fad84cc305103b28d73482b344d7f5b76f39
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1364972]
---
This was fixed in upstream 4.4 kernels. All Fedora releases are currently shipping newer kernels than this which contain the listed fix.
---
Statement:
This issue affects Red Hat Enterprise Linux 6 and 7 kernels. Th
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=45f6fad84cc305103b28d73482b344d7f5b76f39http://rhn.redhat.com/errata/RHSA-2016-0855.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2574.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2584.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2695.htmlhttp://source.android.com/security/bulletin/2016-08-01.htmlhttp://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.3.3http://www.securityfocus.com/bid/92227https://github.com/torvalds/linux/commit/45f6fad84cc305103b28d73482b344d7f5b76f39http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=45f6fad84cc305103b28d73482b344d7f5b76f39http://rhn.redhat.com/errata/RHSA-2016-0855.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2574.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2584.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2695.htmlhttp://source.android.com/security/bulletin/2016-08-01.htmlhttp://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.3.3http://www.securityfocus.com/bid/92227https://github.com/torvalds/linux/commit/45f6fad84cc305103b28d73482b344d7f5b76f39
2016-08-06
Published