CVE-2016-4997
published 2016-07-03CVE-2016-4997: The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users…
PriorityP354high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EXPLOIT
EPSS
5.68%
92.1th percentile
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corruption) by leveraging in-container root access to provide a crafted offset value that triggers an unintended decrement.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.6.2-2 (bookworm) | linux 4.6.2-2 (bookworm) |
| linux | linux_kernel | >= 0 < 4.6.2-2 | 4.6.2-2 |
| linux | linux_kernel | >= 0 < 4.6.2-2 | 4.6.2-2 |
| linux | linux_kernel | >= 0 < 4.6.2-2 | 4.6.2-2 |
| linux | linux_kernel | >= 0 < 4.6.2-2 | 4.6.2-2 |
| linux | linux_kernel | >= 0 < 3.13.0-91.138 | 3.13.0-91.138 |
| linux | linux_kernel | >= 0 < 4.4.0-28.47 | 4.4.0-28.47 |
| linux | linux_kernel | >= 2.6.17 < 3.2.80 | 3.2.80 |
| linux | linux_kernel | >= 3.11 < 3.12.62 | 3.12.62 |
| linux | linux_kernel | >= 3.13 < 3.14.73 | 3.14.73 |
| linux | linux_kernel | >= 3.15 < 3.16.37 | 3.16.37 |
| linux | linux_kernel | >= 3.17 < 3.18.37 | 3.18.37 |
| linux | linux_kernel | >= 3.19 < 4.1.28 | 4.1.28 |
| linux | linux_kernel | >= 3.3 < 3.10.103 | 3.10.103 |
| linux | linux_kernel | >= 4.2 < 4.4.14 | 4.4.14 |
| linux | linux_kernel | >= 4.5 < 4.6.3 | 4.6.3 |
| novell | suse_linux_enterprise_desktop | — | — |
| novell | suse_linux_enterprise_live_patching | — | — |
| novell | suse_linux_enterprise_module_for_public_cloud | — | — |
| novell | suse_linux_enterprise_real_time_extension | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel regression
vendor_ubuntu·2017-06-29·CVSS 7.8
CVE-2017-1000364 [HIGH] Linux kernel regression
Title: Linux kernel regression
Summary: Several security issues were fixed in the Linux kernel.
USN-3338-1 fixed vulnerabilities in the Linux kernel. However, the fix
for CVE-2017-1000364 introduced regressions for some Java applications.
This update addresses the issue. We apologize for the inconvenience.
Original advisory details:
It was discovered that the stack guard page for processes in the Linux
kernel was not sufficiently large enough to prevent overlapping with the
heap. An attacker could leverage this with another vulnerability to execute
arbitrary code and gain administrative privileges (CVE-2017-1000364)
Jesse Hertz and Tim Newsham discovered that the Linux netfilter
implementation did not correctly perform validation when handling 32 bit
compatibility IPT_SO_SET_REPLACE e
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-06-21·CVSS 7.8
CVE-2016-4997 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the stack guard page for processes in the Linux
kernel was not sufficiently large enough to prevent overlapping with the
heap. An attacker could leverage this with another vulnerability to execute
arbitrary code and gain administrative privileges (CVE-2017-1000364)
Jesse Hertz and Tim Newsham discovered that the Linux netfilter
implementation did not correctly perform validation when handling 32 bit
compatibility IPT_SO_SET_REPLACE events on 64 bit platforms. A local
unprivileged attacker could use this to cause a denial of service (system
crash) or execute arbitrary code with administrative privileges.
(CVE-2016-4997)
Instructions: After a standard system update
Ubuntu
Linux kernel (Wily HWE) vulnerabilities
vendor_ubuntu·2016-06-27·CVSS 6.2
CVE-2016-4482 [MEDIUM] Linux kernel (Wily HWE) vulnerabilities
Title: Linux kernel (Wily HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
USN-3017-1 fixed vulnerabilities in the Linux kernel for Ubuntu 15.10.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 15.10 for Ubuntu 14.04 LTS.
Jesse Hertz and Tim Newsham discovered that the Linux netfilter
implementation did not correctly perform validation when handling 32 bit
compatibility IPT_SO_SET_REPLACE events on 64 bit platforms. A local
unprivileged attacker could use this to cause a denial of service (system
crash) or execute arbitrary code with administrative privileges.
(CVE-2016-4997)
Kangjie Lu discovered an information leak in the core USB implementation in
the Linux kernel. A local attacker could use thi
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities
vendor_ubuntu·2016-06-27·CVSS 6.2
CVE-2016-4482 [MEDIUM] Linux kernel (Vivid HWE) vulnerabilities
Title: Linux kernel (Vivid HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jesse Hertz and Tim Newsham discovered that the Linux netfilter
implementation did not correctly perform validation when handling 32 bit
compatibility IPT_SO_SET_REPLACE events on 64 bit platforms. A local
unprivileged attacker could use this to cause a denial of service (system
crash) or execute arbitrary code with administrative privileges.
(CVE-2016-4997)
Kangjie Lu discovered an information leak in the core USB implementation in
the Linux kernel. A local attacker could use this to obtain potentially
sensitive information from kernel memory. (CVE-2016-4482)
Kangjie Lu discovered an information leak in the timer handling
implementation in the Advanced Linux Sound Architecture (A
Ubuntu
Linux kernel (Qualcomm Snapdragon) vulnerabilities
vendor_ubuntu·2016-06-27·CVSS 6.2
CVE-2016-4482 [MEDIUM] Linux kernel (Qualcomm Snapdragon) vulnerabilities
Title: Linux kernel (Qualcomm Snapdragon) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jesse Hertz and Tim Newsham discovered that the Linux netfilter
implementation did not correctly perform validation when handling 32 bit
compatibility IPT_SO_SET_REPLACE events on 64 bit platforms. A local
unprivileged attacker could use this to cause a denial of service (system
crash) or execute arbitrary code with administrative privileges.
(CVE-2016-4997)
Kangjie Lu discovered an information leak in the core USB implementation in
the Linux kernel. A local attacker could use this to obtain potentially
sensitive information from kernel memory. (CVE-2016-4482)
Kangjie Lu discovered an information leak in the timer handling
implementation in the Advanced Linux Sound Archi
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-06-27·CVSS 6.2
CVE-2016-4482 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jesse Hertz and Tim Newsham discovered that the Linux netfilter
implementation did not correctly perform validation when handling 32 bit
compatibility IPT_SO_SET_REPLACE events on 64 bit platforms. A local
unprivileged attacker could use this to cause a denial of service (system
crash) or execute arbitrary code with administrative privileges.
(CVE-2016-4997)
Kangjie Lu discovered an information leak in the core USB implementation in
the Linux kernel. A local attacker could use this to obtain potentially
sensitive information from kernel memory. (CVE-2016-4482)
Kangjie Lu discovered an information leak in the timer handling
implementation in the Advanced Linux Sound Architecture (ALSA) subsyst
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2016-06-27·CVSS 6.2
CVE-2016-4482 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
USN-3016-1 fixed vulnerabilities in the Linux kernel for Ubuntu
16.04 LTS. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for
Ubuntu 14.04 LTS.
Jesse Hertz and Tim Newsham discovered that the Linux netfilter
implementation did not correctly perform validation when handling 32 bit
compatibility IPT_SO_SET_REPLACE events on 64 bit platforms. A local
unprivileged attacker could use this to cause a denial of service (system
crash) or execute arbitrary code with administrative privileges.
(CVE-2016-4997)
Kangjie Lu discovered an information leak in the core USB implementation in
the Linux kernel. A local attacker cou
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2016-06-27·CVSS 6.2
CVE-2016-4482 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
USN-3018-1 fixed vulnerabilities in the Linux kernel for Ubuntu
14.04 LTS. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for
Ubuntu 12.04 LTS.
Jesse Hertz and Tim Newsham discovered that the Linux netfilter
implementation did not correctly perform validation when handling 32 bit
compatibility IPT_SO_SET_REPLACE events on 64 bit platforms. A local
unprivileged attacker could use this to cause a denial of service (system
crash) or execute arbitrary code with administrative privileges.
(CVE-2016-4997)
Kangjie Lu discovered an information leak in the core USB implementation in
the Linux kernel. A local attacker cou
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2016-06-27·CVSS 6.2
CVE-2016-4482 [MEDIUM] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jesse Hertz and Tim Newsham discovered that the Linux netfilter
implementation did not correctly perform validation when handling 32 bit
compatibility IPT_SO_SET_REPLACE events on 64 bit platforms. A local
unprivileged attacker could use this to cause a denial of service (system
crash) or execute arbitrary code with administrative privileges.
(CVE-2016-4997)
Kangjie Lu discovered an information leak in the core USB implementation in
the Linux kernel. A local attacker could use this to obtain potentially
sensitive information from kernel memory. (CVE-2016-4482)
Jann Horn discovered that the InfiniBand interfaces within the Linux kernel
could be coerced into overwriting kernel memo
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-06-27·CVSS 6.2
CVE-2016-4482 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jesse Hertz and Tim Newsham discovered that the Linux netfilter
implementation did not correctly perform validation when handling 32 bit
compatibility IPT_SO_SET_REPLACE events on 64 bit platforms. A local
unprivileged attacker could use this to cause a denial of service (system
crash) or execute arbitrary code with administrative privileges.
(CVE-2016-4997)
Kangjie Lu discovered an information leak in the core USB implementation in
the Linux kernel. A local attacker could use this to obtain potentially
sensitive information from kernel memory. (CVE-2016-4482)
Jann Horn discovered that the InfiniBand interfaces within the Linux kernel
could be coerced into overwriting kernel memory. A local u
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2016-06-27·CVSS 6.2
CVE-2016-4482 [MEDIUM] Linux kernel (Raspberry Pi 2) vulnerabilities
Title: Linux kernel (Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jesse Hertz and Tim Newsham discovered that the Linux netfilter
implementation did not correctly perform validation when handling 32 bit
compatibility IPT_SO_SET_REPLACE events on 64 bit platforms. A local
unprivileged attacker could use this to cause a denial of service (system
crash) or execute arbitrary code with administrative privileges.
(CVE-2016-4997)
Kangjie Lu discovered an information leak in the core USB implementation in
the Linux kernel. A local attacker could use this to obtain potentially
sensitive information from kernel memory. (CVE-2016-4482)
Kangjie Lu discovered an information leak in the timer handling
implementation in the Advanced Linux Sound Architectu
Red Hat
kernel: compat IPT_SO_SET_REPLACE setsockopt
vendor_redhat·2016-06-24·CVSS 7.8
CVE-2016-4997 [HIGH] CWE-20 kernel: compat IPT_SO_SET_REPLACE setsockopt
kernel: compat IPT_SO_SET_REPLACE setsockopt
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corruption) by leveraging in-container root access to provide a crafted offset value that triggers an unintended decrement.
A flaw was discovered in processing setsockopt for 32 bit processes on 64 bit systems. This flaw will allow attackers to alter arbitrary kernel memory when unloading a kernel module. This action is usually restricted to root-privileged users but can also be leveraged if the kernel is compiled with CONFIG_USER_NS and CONFIG_NET_NS and the user is granted elevated privileges.
Statement: This issue affects the Li
Debian
CVE-2016-4997: linux - The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations...
vendor_debian·2016·CVSS 7.8
CVE-2016-4997 [HIGH] CVE-2016-4997: linux - The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations...
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corruption) by leveraging in-container root access to provide a crafted offset value that triggers an unintended decrement.
Scope: local
bookworm: resolved (fixed in 4.6.2-2)
bullseye: resolved (fixed in 4.6.2-2)
forky: resolved (fixed in 4.6.2-2)
sid: resolved (fixed in 4.6.2-2)
trixie: resolved (fixed in 4.6.2-2)
GHSA
GHSA-qc28-hwmc-pw94: The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4
ghsa_unreviewed·2022-05-13
CVE-2016-4997 [HIGH] GHSA-qc28-hwmc-pw94: The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corruption) by leveraging in-container root access to provide a crafted offset value that triggers an unintended decrement.
OSV
CVE-2016-4997: The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4
osv·2016-07-03·CVSS 7.8
CVE-2016-4997 [HIGH] CVE-2016-4997: The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corruption) by leveraging in-container root access to provide a crafted offset value that triggers an unintended decrement.
OSV
linux-lts-xenial vulnerabilities
osv·2016-06-27·CVSS 6.2
[MEDIUM] linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
USN-3016-1 fixed vulnerabilities in the Linux kernel for Ubuntu
16.04 LTS. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for
Ubuntu 14.04 LTS.
Jesse Hertz and Tim Newsham discovered that the Linux netfilter
implementation did not correctly perform validation when handling 32 bit
compatibility IPT_SO_SET_REPLACE events on 64 bit platforms. A local
unprivileged attacker could use this to cause a denial of service (system
crash) or execute arbitrary code with administrative privileges.
(CVE-2016-4997)
Kangjie Lu discovered an information leak in the core USB implementation in
the Linux kernel. A local attacker could use this to obtain potentially
sensitive information from kernel memory.
OSV
linux vulnerabilities
osv·2016-06-27·CVSS 6.2
CVE-2016-4997 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Jesse Hertz and Tim Newsham discovered that the Linux netfilter
implementation did not correctly perform validation when handling 32 bit
compatibility IPT_SO_SET_REPLACE events on 64 bit platforms. A local
unprivileged attacker could use this to cause a denial of service (system
crash) or execute arbitrary code with administrative privileges.
(CVE-2016-4997)
Kangjie Lu discovered an information leak in the core USB implementation in
the Linux kernel. A local attacker could use this to obtain potentially
sensitive information from kernel memory. (CVE-2016-4482)
Kangjie Lu discovered an information leak in the timer handling
implementation in the Advanced Linux Sound Architecture (ALSA) subsystem of
the Linux kernel. A local attacker could use this to obtain potentia
OSV
linux-lts-wily vulnerabilities
osv·2016-06-27·CVSS 6.2
[MEDIUM] linux-lts-wily vulnerabilities
linux-lts-wily vulnerabilities
USN-3017-1 fixed vulnerabilities in the Linux kernel for Ubuntu 15.10.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 15.10 for Ubuntu 14.04 LTS.
Jesse Hertz and Tim Newsham discovered that the Linux netfilter
implementation did not correctly perform validation when handling 32 bit
compatibility IPT_SO_SET_REPLACE events on 64 bit platforms. A local
unprivileged attacker could use this to cause a denial of service (system
crash) or execute arbitrary code with administrative privileges.
(CVE-2016-4997)
Kangjie Lu discovered an information leak in the core USB implementation in
the Linux kernel. A local attacker could use this to obtain potentially
sensitive information from kernel memory. (CVE-2016-
OSV
linux-snapdragon vulnerabilities
osv·2016-06-27·CVSS 6.2
CVE-2016-4997 [MEDIUM] linux-snapdragon vulnerabilities
linux-snapdragon vulnerabilities
Jesse Hertz and Tim Newsham discovered that the Linux netfilter
implementation did not correctly perform validation when handling 32 bit
compatibility IPT_SO_SET_REPLACE events on 64 bit platforms. A local
unprivileged attacker could use this to cause a denial of service (system
crash) or execute arbitrary code with administrative privileges.
(CVE-2016-4997)
Kangjie Lu discovered an information leak in the core USB implementation in
the Linux kernel. A local attacker could use this to obtain potentially
sensitive information from kernel memory. (CVE-2016-4482)
Kangjie Lu discovered an information leak in the timer handling
implementation in the Advanced Linux Sound Architecture (ALSA) subsystem of
the Linux kernel. A local attacker could use this to obta
OSV
linux-lts-vivid vulnerabilities
osv·2016-06-27·CVSS 6.2
CVE-2016-4997 [MEDIUM] linux-lts-vivid vulnerabilities
linux-lts-vivid vulnerabilities
Jesse Hertz and Tim Newsham discovered that the Linux netfilter
implementation did not correctly perform validation when handling 32 bit
compatibility IPT_SO_SET_REPLACE events on 64 bit platforms. A local
unprivileged attacker could use this to cause a denial of service (system
crash) or execute arbitrary code with administrative privileges.
(CVE-2016-4997)
Kangjie Lu discovered an information leak in the core USB implementation in
the Linux kernel. A local attacker could use this to obtain potentially
sensitive information from kernel memory. (CVE-2016-4482)
Kangjie Lu discovered an information leak in the timer handling
implementation in the Advanced Linux Sound Architecture (ALSA) subsystem of
the Linux kernel. A local attacker could use this to obtai
OSV
linux-lts-utopic vulnerabilities
osv·2016-06-27·CVSS 6.2
CVE-2016-4997 [MEDIUM] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
Jesse Hertz and Tim Newsham discovered that the Linux netfilter
implementation did not correctly perform validation when handling 32 bit
compatibility IPT_SO_SET_REPLACE events on 64 bit platforms. A local
unprivileged attacker could use this to cause a denial of service (system
crash) or execute arbitrary code with administrative privileges.
(CVE-2016-4997)
Kangjie Lu discovered an information leak in the core USB implementation in
the Linux kernel. A local attacker could use this to obtain potentially
sensitive information from kernel memory. (CVE-2016-4482)
Jann Horn discovered that the InfiniBand interfaces within the Linux kernel
could be coerced into overwriting kernel memory. A local unprivileged
attacker could use this to possibly gain administra
OSV
linux-raspi2 vulnerabilities
osv·2016-06-27·CVSS 6.2
CVE-2016-4997 [MEDIUM] linux-raspi2 vulnerabilities
linux-raspi2 vulnerabilities
Jesse Hertz and Tim Newsham discovered that the Linux netfilter
implementation did not correctly perform validation when handling 32 bit
compatibility IPT_SO_SET_REPLACE events on 64 bit platforms. A local
unprivileged attacker could use this to cause a denial of service (system
crash) or execute arbitrary code with administrative privileges.
(CVE-2016-4997)
Kangjie Lu discovered an information leak in the core USB implementation in
the Linux kernel. A local attacker could use this to obtain potentially
sensitive information from kernel memory. (CVE-2016-4482)
Kangjie Lu discovered an information leak in the timer handling
implementation in the Advanced Linux Sound Architecture (ALSA) subsystem of
the Linux kernel. A local attacker could use this to obtain p
OSV
linux vulnerabilities
osv·2016-06-27·CVSS 6.2
CVE-2016-4997 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Jesse Hertz and Tim Newsham discovered that the Linux netfilter
implementation did not correctly perform validation when handling 32 bit
compatibility IPT_SO_SET_REPLACE events on 64 bit platforms. A local
unprivileged attacker could use this to cause a denial of service (system
crash) or execute arbitrary code with administrative privileges.
(CVE-2016-4997)
Kangjie Lu discovered an information leak in the core USB implementation in
the Linux kernel. A local attacker could use this to obtain potentially
sensitive information from kernel memory. (CVE-2016-4482)
Jann Horn discovered that the InfiniBand interfaces within the Linux kernel
could be coerced into overwriting kernel memory. A local unprivileged
attacker could use this to possibly gain administrative privil
No detection rules found.
Exploit-DB
Linux Kernel 4.6.2 (Ubuntu 16.04.1) - 'IP6T_SO_SET_REPLACE' Local Privilege Escalation
exploitdb·2016-10-10·CVSS 7.8
CVE-2016-4997 [HIGH] Linux Kernel 4.6.2 (Ubuntu 16.04.1) - 'IP6T_SO_SET_REPLACE' Local Privilege Escalation
Linux Kernel 4.6.2 (Ubuntu 16.04.1) - 'IP6T_SO_SET_REPLACE' Local Privilege Escalation
---
# Exploit Title: Linux kernel <= 4.6.2 - Local Privileges Escalation via IP6T_SO_SET_REPLACE compat setsockopt call
# Date: 2016.10.8
# Exploit Author: Qian Zhang@MarvelTeam Qihoo 360
# Version: Linux kernel <= 4.6.2
# Tested on: Ubuntu 16.04.1 LTS Linux 4.4.0-21-generic
# CVE: CVE-2016-4997
# Reference:http://www.openwall.com/lists/oss-security/2016/09/29/10
# Contact: [email protected]
#DESCRIPTION
#===========
#The IPv6 netfilter subsystem in the Linux kernel through 4.6.2 does not validate certain offset fields,
#which allows local users to escalade privileges via an IP6T_SO_SET_REPLACE compat setsockopt call with ip6_tables module loaded.
zhang_q@ubuntu:~/ipv6_IP6T_SO_SET_REPLACE$ ls
comp
Exploit-DB
Linux Kernel 4.6.3 (x86) - 'Netfilter' Local Privilege Escalation (Metasploit)
exploitdb·2016-09-27
CVE-2016-4997 Linux Kernel 4.6.3 (x86) - 'Netfilter' Local Privilege Escalation (Metasploit)
Linux Kernel 4.6.3 (x86) - 'Netfilter' Local Privilege Escalation (Metasploit)
---
##
# This module requires Metasploit: http://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require "msf/core"
class MetasploitModule 'Linux Kernel 4.6.3 Netfilter Privilege Escalation',
'Description' => %q{
This module attempts to exploit a netfilter bug on Linux Kernels befoe 4.6.3, and currently
only works against Ubuntu 16.04 (not 16.04.1) with kernel
4.4.0-21-generic.
Several conditions have to be met for successful exploitation:
Ubuntu:
1. ip_tables.ko (ubuntu), iptable_raw (fedora) has to be loaded (root running iptables -L will do such)
2. libc6-dev-i386 (ubuntu), glibc-devel.i686 & libgcc.i686 (fedora) needs to be installed to compile
Kernel 4.4.0-31-
Metasploit
Linux Kernel 4.6.3 Netfilter Privilege Escalation
metasploit
Linux Kernel 4.6.3 Netfilter Privilege Escalation
Linux Kernel 4.6.3 Netfilter Privilege Escalation
This module attempts to exploit a netfilter bug on Linux Kernels before 4.6.3, and currently only works against Ubuntu 16.04 (not 16.04.1) with kernel 4.4.0-21-generic. Several conditions have to be met for successful exploitation: Ubuntu: 1. ip_tables.ko (ubuntu), iptable_raw (fedora) has to be loaded (root running iptables -L will do such) 2. libc6-dev-i386 (ubuntu), glibc-devel.i686 & libgcc.i686 (fedora) needs to be installed to compile Kernel 4.4.0-31-generic and newer are not vulnerable. This exploit does not bypass SMEP/SMAP. We write the ascii files and compile on target instead of locally since metasm bombs for not having cdefs.h (even if locally installed)
Bugzilla
CVE-2016-4997 compat IP6T_SO_SET_REPLACE setsockopt
bugzilla·2016-10-10·CVSS 7.8
CVE-2016-4997 [HIGH] CVE-2016-4997 compat IP6T_SO_SET_REPLACE setsockopt
CVE-2016-4997 compat IP6T_SO_SET_REPLACE setsockopt
The IPv6 netfilter subsystem in the Linux kernel through 4.6.2 does not validate certain offset fields,
which allows local users to escalade privileges via an IP6T_SO_SET_REPLACE compat setsockopt call
The page
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4997
has updated their Description and References sections
Discussion on oss-sec:
http://www.openwall.com/lists/oss-security/2016/09/29/10
Discussion:
*** This bug has been marked as a duplicate of bug 1349722 ***
Bugzilla
CVE-2016-4997 kernel: compat IPT_SO_SET_REPLACE setsockopt [fedora-all]
bugzilla·2016-06-28·CVSS 7.8
CVE-2016-4997 [HIGH] CVE-2016-4997 kernel: compat IPT_SO_SET_REPLACE setsockopt [fedora-all]
CVE-2016-4997 kernel: compat IPT_SO_SET_REPLACE setsockopt [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora
Bugzilla
CVE-2016-4997 kernel: compat IPT_SO_SET_REPLACE setsockopt
bugzilla·2016-06-24·CVSS 7.8
CVE-2016-4997 [HIGH] CVE-2016-4997 kernel: compat IPT_SO_SET_REPLACE setsockopt
CVE-2016-4997 kernel: compat IPT_SO_SET_REPLACE setsockopt
A flaw was discovered in processing setsockopt for 32 bit processes on
64 bit systems. This flaw will allow attackers to alter arbitary kernel
memory when unloading a kernel module. This action is usually restricted
to root-priveledged users but can also be leveraged if the kernel is
compiled with CONFIG_USER_NS and CONFIG_NET_NS and the user is granted elevated priveledges.
This flaw was introduced in commit 52e804c6dfaa,
Upstream fixes
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ce683e5f9d04
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6e94e0cfb088
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=bdf533de6968
Discussion on oss-sec:
http://ww
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ce683e5f9d045e5d67d1312a42b359cb2ab2a13chttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00060.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00061.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00048.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00050.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00051.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00052.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00053.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1847.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1875.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1883.htmlhttp://www.debian.org/security/2016/dsa-3607http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.6.3http://www.openwall.com/lists/oss-security/2016/06/24/5http://www.openwall.com/lists/oss-security/2016/09/29/10http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.htmlhttp://www.securityfocus.com/bid/91451http://www.securitytracker.com/id/1036171http://www.ubuntu.com/usn/USN-3016-1http://www.ubuntu.com/usn/USN-3016-2http://www.ubuntu.com/usn/USN-3016-3http://www.ubuntu.com/usn/USN-3016-4http://www.ubuntu.com/usn/USN-3017-1http://www.ubuntu.com/usn/USN-3017-2http://www.ubuntu.com/usn/USN-3017-3http://www.ubuntu.com/usn/USN-3018-1http://www.ubuntu.com/usn/USN-3018-2http://www.ubuntu.com/usn/USN-3019-1http://www.ubuntu.com/usn/USN-3020-1https://bugzilla.redhat.com/show_bug.cgi?id=1349722https://github.com/nccgroup/TriforceLinuxSyscallFuzzer/tree/master/crash_reports/report_compatIpthttps://github.com/torvalds/linux/commit/ce683e5f9d045e5d67d1312a42b359cb2ab2a13chttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05347541https://www.exploit-db.com/exploits/40435/https://www.exploit-db.com/exploits/40489/http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ce683e5f9d045e5d67d1312a42b359cb2ab2a13chttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00060.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00061.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00048.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00050.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00051.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00052.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00053.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1847.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1875.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1883.htmlhttp://www.debian.org/security/2016/dsa-3607http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.6.3http://www.openwall.com/lists/oss-security/2016/06/24/5http://www.openwall.com/lists/oss-security/2016/09/29/10http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.htmlhttp://www.securityfocus.com/bid/91451http://www.securitytracker.com/id/1036171http://www.ubuntu.com/usn/USN-3016-1http://www.ubuntu.com/usn/USN-3016-2http://www.ubuntu.com/usn/USN-3016-3http://www.ubuntu.com/usn/USN-3016-4http://www.ubuntu.com/usn/USN-3017-1http://www.ubuntu.com/usn/USN-3017-2http://www.ubuntu.com/usn/USN-3017-3http://www.ubuntu.com/usn/USN-3018-1http://www.ubuntu.com/usn/USN-3018-2http://www.ubuntu.com/usn/USN-3019-1http://www.ubuntu.com/usn/USN-3020-1https://bugzilla.redhat.com/show_bug.cgi?id=1349722https://github.com/nccgroup/TriforceLinuxSyscallFuzzer/tree/master/crash_reports/report_compatIpthttps://github.com/torvalds/linux/commit/ce683e5f9d045e5d67d1312a42b359cb2ab2a13chttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05347541https://www.exploit-db.com/exploits/40435/https://www.exploit-db.com/exploits/40489/
2016-07-03
Published