CVE-2016-4805
published 2016-05-23CVE-2016-4805: Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory…
PriorityP335high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.48%
38.3th percentile
Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a network namespace, related to the ppp_register_net_channel and ppp_unregister_channel functions.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 4.5.2-1 (bookworm) | linux 4.5.2-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | >= 0 < 4.5.2-1 | 4.5.2-1 |
| linux | linux_kernel | >= 0 < 4.5.2-1 | 4.5.2-1 |
| linux | linux_kernel | >= 0 < 4.5.2-1 | 4.5.2-1 |
| linux | linux_kernel | >= 0 < 4.5.2-1 | 4.5.2-1 |
| linux | linux_kernel | >= 2.6.30 < 3.2.80 | 3.2.80 |
| linux | linux_kernel | >= 3.11 < 3.12.59 | 3.12.59 |
| linux | linux_kernel | >= 3.13 < 3.14.67 | 3.14.67 |
| linux | linux_kernel | >= 3.15 < 3.16.35 | 3.16.35 |
| linux | linux_kernel | >= 3.17 < 3.18.37 | 3.18.37 |
| linux | linux_kernel | >= 3.19 < 4.1.28 | 4.1.28 |
| linux | linux_kernel | >= 3.3 < 3.10.102 | 3.10.102 |
| linux | linux_kernel | >= 4.2 < 4.4.8 | 4.4.8 |
| linux | linux_kernel | >= 4.5 < 4.5.2 | 4.5.2 |
| novell | opensuse_leap | — | — |
| novell | suse_linux_enterprise_desktop | — | — |
| novell | suse_linux_enterprise_live_patching | — | — |
| novell | suse_linux_enterprise_module_for_public_cloud | — | — |
| novell | suse_linux_enterprise_real_time_extension | — | — |
| novell | suse_linux_enterprise_real_time_extension | — | — |
| novell | suse_linux_enterprise_server | — | — |
| novell | suse_linux_enterprise_server | — | — |
| novell | suse_linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jwg9-q35h-9vwx: Use-after-free vulnerability in drivers/net/ppp/ppp_generic
ghsa_unreviewed·2022-05-13
CVE-2016-4805 [HIGH] CWE-416 GHSA-jwg9-q35h-9vwx: Use-after-free vulnerability in drivers/net/ppp/ppp_generic
Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a network namespace, related to the ppp_register_net_channel and ppp_unregister_channel functions.
OSV
CVE-2016-4805: Use-after-free vulnerability in drivers/net/ppp/ppp_generic
osv·2016-05-23·CVSS 7.8
CVE-2016-4805 [HIGH] CVE-2016-4805: Use-after-free vulnerability in drivers/net/ppp/ppp_generic
Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a network namespace, related to the ppp_register_net_channel and ppp_unregister_channel functions.
Android
CVE-2016-4805: Android Security Bulletin 2016-09-01
CVE: CVE-2016-4805
Severity: HIGH
References: A-28979703
Upstream
kernel
vendor_android·2016-09-01·CVSS 7.8
CVE-2016-4805 [HIGH] CVE-2016-4805: Android Security Bulletin 2016-09-01
CVE: CVE-2016-4805
Severity: HIGH
References: A-28979703
Upstream
kernel
Android Security Bulletin 2016-09-01
CVE: CVE-2016-4805
Severity: HIGH
References: A-28979703
Upstream
kernel
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-06-27·CVSS 4.6
CVE-2016-3951 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrey Konovalov discovered that the CDC Network Control Model USB driver
in the Linux kernel did not cancel work events queued if a later error
occurred, resulting in a use-after-free. An attacker with physical access
could use this to cause a denial of service (system crash). (CVE-2016-3951)
Kangjie Lu discovered an information leak in the core USB implementation in
the Linux kernel. A local attacker could use this to obtain potentially
sensitive information from kernel memory. (CVE-2016-4482)
Jann Horn discovered that the InfiniBand interfaces within the Linux kernel
could be coerced into overwriting kernel memory. A local unprivileged
attacker could use this to possibly gain administrativ
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2016-06-27·CVSS 4.6
CVE-2016-3951 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrey Konovalov discovered that the CDC Network Control Model USB driver
in the Linux kernel did not cancel work events queued if a later error
occurred, resulting in a use-after-free. An attacker with physical access
could use this to cause a denial of service (system crash). (CVE-2016-3951)
Kangjie Lu discovered an information leak in the core USB implementation in
the Linux kernel. A local attacker could use this to obtain potentially
sensitive information from kernel memory. (CVE-2016-4482)
Jann Horn discovered that the InfiniBand interfaces within the Linux kernel
could be coerced into overwriting kernel memory. A local unprivileged
attacker could use this to possibly gain admin
Red Hat
kernel: Use after free vulnerability in ppp_unregister_channel
vendor_redhat·2016-03-16·CVSS 7.8
CVE-2016-4805 [HIGH] CWE-416 kernel: Use after free vulnerability in ppp_unregister_channel
kernel: Use after free vulnerability in ppp_unregister_channel
Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a network namespace, related to the ppp_register_net_channel and ppp_unregister_channel functions.
A use after free vulnerability was found in ppp_unregister_channel function. This is triggered when network namespace is removed while ppp_async channel is still registered in it and ppp_unregister_channel() tries to access its per-netns data in the defunct namespace. An attacker controlling this data could potentially denial of service the system.
Statement: This issue affects the Lin
Debian
CVE-2016-4805: linux - Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kerne...
vendor_debian·2016·CVSS 7.8
CVE-2016-4805 [HIGH] CVE-2016-4805: linux - Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kerne...
Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a network namespace, related to the ppp_register_net_channel and ppp_unregister_channel functions.
Scope: local
bookworm: resolved (fixed in 4.5.2-1)
bullseye: resolved (fixed in 4.5.2-1)
forky: resolved (fixed in 4.5.2-1)
sid: resolved (fixed in 4.5.2-1)
trixie: resolved (fixed in 4.5.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-4805 kernel: Use after free vulnerability in ppp_unregister_channel
bugzilla·2016-05-13·CVSS 7.8
CVE-2016-4805 [HIGH] CVE-2016-4805 kernel: Use after free vulnerability in ppp_unregister_channel
CVE-2016-4805 kernel: Use after free vulnerability in ppp_unregister_channel
A use after free vulnerability was found in ppp_unregister_channel function. This is triggered when network namespace is removed while ppp_async channel is still registered in it and ppp_unregister_channel() tries to access its per-netns data in the defunct namespace.
An attacker who could control this memory that is being used in the defunct namespace could create a denial of service by spinlocking a CPU.
An unprivileged local user could use this flaw to induce kernel memory corruption on the system, leading to a crash. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.
Upstream patch:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.
Bugzilla
CVE-2016-4805 kernel: Use after free vulnerability in ppp_unregister_channel [fedora-all]
bugzilla·2016-05-13·CVSS 7.8
CVE-2016-4805 [HIGH] CVE-2016-4805 kernel: Use after free vulnerability in ppp_unregister_channel [fedora-all]
CVE-2016-4805 kernel: Use after free vulnerability in ppp_unregister_channel [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1f461dcdd296eecedaffffc6bae2bfa90bd7eb89http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.htmlhttp://www.debian.org/security/2016/dsa-3607http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.2http://www.openwall.com/lists/oss-security/2016/05/15/2http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.htmlhttp://www.securityfocus.com/bid/90605http://www.securitytracker.com/id/1036763http://www.ubuntu.com/usn/USN-3021-1http://www.ubuntu.com/usn/USN-3021-2https://bugzilla.redhat.com/show_bug.cgi?id=1335803https://github.com/torvalds/linux/commit/1f461dcdd296eecedaffffc6bae2bfa90bd7eb89http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1f461dcdd296eecedaffffc6bae2bfa90bd7eb89http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.htmlhttp://www.debian.org/security/2016/dsa-3607http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.2http://www.openwall.com/lists/oss-security/2016/05/15/2http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.htmlhttp://www.securityfocus.com/bid/90605http://www.securitytracker.com/id/1036763http://www.ubuntu.com/usn/USN-3021-1http://www.ubuntu.com/usn/USN-3021-2https://bugzilla.redhat.com/show_bug.cgi?id=1335803https://github.com/torvalds/linux/commit/1f461dcdd296eecedaffffc6bae2bfa90bd7eb89
2016-05-23
Published