CVE-2016-5243
published 2016-06-27CVE-2016-5243: The tipc_nl_compat_link_dump function in net/tipc/netlink_compat.c in the Linux kernel through 4.6.3 does not properly copy a certain string, which allows…
PriorityP422medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.50%
40.2th percentile
The tipc_nl_compat_link_dump function in net/tipc/netlink_compat.c in the Linux kernel through 4.6.3 does not properly copy a certain string, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.6.2-1 (bookworm) | linux 4.6.2-1 (bookworm) |
| linux | linux_kernel | <= 4.6.3 | — |
| linux | linux_kernel | >= 0 < 4.6.2-1 | 4.6.2-1 |
| linux | linux_kernel | >= 0 < 4.6.2-1 | 4.6.2-1 |
| linux | linux_kernel | >= 0 < 4.6.2-1 | 4.6.2-1 |
| linux | linux_kernel | >= 0 < 4.6.2-1 | 4.6.2-1 |
| linux | linux_kernel | >= 0 < 3.13.0-93.140 | 3.13.0-93.140 |
| linux | linux_kernel | >= 0 < 4.4.0-34.53 | 4.4.0-34.53 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv7.8HIGH
vendor_ubuntu8.4HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-08-10·CVSS 5.5
CVE-2016-4470 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Kangjie Lu discovered an information leak in the netlink implementation of
the Linux kernel. A local attacker could use this to obtain sensitive
information from kernel memory. (CVE-2016-5243)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to rec
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2016-08-10·CVSS 7.8
CVE-2016-3135 [HIGH] Linux kernel (Raspberry Pi 2) vulnerabilities
Title: Linux kernel (Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hawkes discovered an integer overflow in the Linux netfilter
implementation. On systems running 32 bit kernels, a local unprivileged
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code with administrative privileges.
(CVE-2016-3135)
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Sasha Levin discovered that a use-after-free existed in the percpu
allocator in the Linux kernel. A local attacker could use thi
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-08-10·CVSS 7.8
CVE-2016-3135 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hawkes discovered an integer overflow in the Linux netfilter
implementation. On systems running 32 bit kernels, a local unprivileged
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code with administrative privileges.
(CVE-2016-3135)
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Sasha Levin discovered that a use-after-free existed in the percpu
allocator in the Linux kernel. A local attacker could use this to cause a
deni
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities
vendor_ubuntu·2016-08-10·CVSS 5.5
CVE-2016-1237 [MEDIUM] Linux kernel (Vivid HWE) vulnerabilities
Title: Linux kernel (Vivid HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Sasha Levin discovered that a use-after-free existed in the percpu
allocator in the Linux kernel. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code with
administrative privileges. (CVE-2016-4
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-08-10·CVSS 8.4
CVE-2016-3134 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hawkes discovered that the Linux netfilter implementation did not
correctly perform validation when handling IPT_SO_SET_REPLACE events. A
local unprivileged attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code with administrative
privileges. (CVE-2016-3134)
Vitaly Kuznetsov discovered that the Linux kernel did not properly suppress
hugetlbfs support in X86 paravirtualized guests. An attacker in the guest
OS could cause a denial of service (guest system crash). (CVE-2016-3961)
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition o
Ubuntu
Linux kernel (Qualcomm Snapdragon) vulnerabilities
vendor_ubuntu·2016-08-10·CVSS 7.8
CVE-2016-3135 [HIGH] Linux kernel (Qualcomm Snapdragon) vulnerabilities
Title: Linux kernel (Qualcomm Snapdragon) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hawkes discovered an integer overflow in the Linux netfilter
implementation. On systems running 32 bit kernels, a local unprivileged
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code with administrative privileges.
(CVE-2016-3135)
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Sasha Levin discovered that a use-after-free existed in the percpu
allocator in the Linux kernel. A local attacker could us
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2016-08-10·CVSS 7.8
CVE-2016-3135 [HIGH] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hawkes discovered an integer overflow in the Linux netfilter
implementation. On systems running 32 bit kernels, a local unprivileged
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code with administrative privileges.
(CVE-2016-3135)
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Sasha Levin discovered that a use-after-free existed in the percpu
allocator in the Linux kernel. A local attacker could use this to
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2016-08-10·CVSS 5.5
CVE-2016-4470 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Kangjie Lu discovered an information leak in the netlink implementation of
the Linux kernel. A local attacker could use this to obtain sensitive
information from kernel memory. (CVE-2016-5243)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requir
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2016-08-10·CVSS 8.4
CVE-2016-3134 [HIGH] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hawkes discovered that the Linux netfilter implementation did not
correctly perform validation when handling IPT_SO_SET_REPLACE events. A
local unprivileged attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code with administrative
privileges. (CVE-2016-3134)
Vitaly Kuznetsov discovered that the Linux kernel did not properly suppress
hugetlbfs support in X86 paravirtualized guests. An attacker in the guest
OS could cause a denial of service (guest system crash). (CVE-2016-3961)
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error con
Red Hat
kernel: Information leak in tipc_nl_compat_link_dump
vendor_redhat·2016-06-03·CVSS 5.5
CVE-2016-5243 [MEDIUM] CWE-200 kernel: Information leak in tipc_nl_compat_link_dump
kernel: Information leak in tipc_nl_compat_link_dump
The tipc_nl_compat_link_dump function in net/tipc/netlink_compat.c in the Linux kernel through 4.6.3 does not properly copy a certain string, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.
A leak of information was possible when issuing a netlink command of the stack memory area leading up to this function call. An attacker could use this to determine stack information for use in a later exploit.
Statement: This issue does not affect Red Hat Enterprise Linux 5,6 or 7 kernels as it does not contain the code that has introduced the flaw.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kerne
Debian
CVE-2016-5243: linux - The tipc_nl_compat_link_dump function in net/tipc/netlink_compat.c in the Linux ...
vendor_debian·2016·CVSS 5.5
CVE-2016-5243 [MEDIUM] CVE-2016-5243: linux - The tipc_nl_compat_link_dump function in net/tipc/netlink_compat.c in the Linux ...
The tipc_nl_compat_link_dump function in net/tipc/netlink_compat.c in the Linux kernel through 4.6.3 does not properly copy a certain string, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.
Scope: local
bookworm: resolved (fixed in 4.6.2-1)
bullseye: resolved (fixed in 4.6.2-1)
forky: resolved (fixed in 4.6.2-1)
sid: resolved (fixed in 4.6.2-1)
trixie: resolved (fixed in 4.6.2-1)
GHSA
GHSA-ccc2-hmwf-w2m2: The tipc_nl_compat_link_dump function in net/tipc/netlink_compat
ghsa_unreviewed·2022-05-17
CVE-2016-5243 [MEDIUM] CWE-200 GHSA-ccc2-hmwf-w2m2: The tipc_nl_compat_link_dump function in net/tipc/netlink_compat
The tipc_nl_compat_link_dump function in net/tipc/netlink_compat.c in the Linux kernel through 4.6.3 does not properly copy a certain string, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.
OSV
linux vulnerabilities
osv·2016-08-10·CVSS 5.5
CVE-2016-4470 [MEDIUM] linux vulnerabilities
linux vulnerabilities
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Kangjie Lu discovered an information leak in the netlink implementation of
the Linux kernel. A local attacker could use this to obtain sensitive
information from kernel memory. (CVE-2016-5243)
OSV
linux vulnerabilities
osv·2016-08-10·CVSS 7.8
CVE-2016-3135 [HIGH] linux vulnerabilities
linux vulnerabilities
Ben Hawkes discovered an integer overflow in the Linux netfilter
implementation. On systems running 32 bit kernels, a local unprivileged
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code with administrative privileges.
(CVE-2016-3135)
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Sasha Levin discovered that a use-after-free existed in the percpu
allocator in the Linux kernel. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code with
admin
OSV
linux-lts-xenial vulnerabilities
osv·2016-08-10·CVSS 7.8
CVE-2016-3135 [HIGH] linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
Ben Hawkes discovered an integer overflow in the Linux netfilter
implementation. On systems running 32 bit kernels, a local unprivileged
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code with administrative privileges.
(CVE-2016-3135)
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Sasha Levin discovered that a use-after-free existed in the percpu
allocator in the Linux kernel. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code
OSV
linux-snapdragon vulnerabilities
osv·2016-08-10·CVSS 7.8
CVE-2016-3135 [HIGH] linux-snapdragon vulnerabilities
linux-snapdragon vulnerabilities
Ben Hawkes discovered an integer overflow in the Linux netfilter
implementation. On systems running 32 bit kernels, a local unprivileged
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code with administrative privileges.
(CVE-2016-3135)
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Sasha Levin discovered that a use-after-free existed in the percpu
allocator in the Linux kernel. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code
OSV
linux-raspi2 vulnerabilities
osv·2016-08-10·CVSS 7.8
CVE-2016-3135 [HIGH] linux-raspi2 vulnerabilities
linux-raspi2 vulnerabilities
Ben Hawkes discovered an integer overflow in the Linux netfilter
implementation. On systems running 32 bit kernels, a local unprivileged
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code with administrative privileges.
(CVE-2016-3135)
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Sasha Levin discovered that a use-after-free existed in the percpu
allocator in the Linux kernel. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code wit
OSV
linux-lts-vivid vulnerabilities
osv·2016-08-10·CVSS 5.5
CVE-2016-1237 [MEDIUM] linux-lts-vivid vulnerabilities
linux-lts-vivid vulnerabilities
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Sasha Levin discovered that a use-after-free existed in the percpu
allocator in the Linux kernel. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code with
administrative privileges. (CVE-2016-4794)
Kangjie Lu discovered an information leak in the netlink implementatio
OSV
CVE-2016-5243: The tipc_nl_compat_link_dump function in net/tipc/netlink_compat
osv·2016-06-27·CVSS 5.5
CVE-2016-5243 [MEDIUM] CVE-2016-5243: The tipc_nl_compat_link_dump function in net/tipc/netlink_compat
The tipc_nl_compat_link_dump function in net/tipc/netlink_compat.c in the Linux kernel through 4.6.3 does not properly copy a certain string, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-5243 kernel: Information leak in tipc_nl_compat_link_dump
bugzilla·2016-06-07·CVSS 5.5
CVE-2016-5243 [MEDIUM] CVE-2016-5243 kernel: Information leak in tipc_nl_compat_link_dump
CVE-2016-5243 kernel: Information leak in tipc_nl_compat_link_dump
A vulnerability was found in the Linux kernel.
There is a char array of size 60 in function tipc_nl_compat_link_dump of file net/tipc/netlink_compat.c, link_info.str. Memory after the NULL byte is not initialized. Sending the whole object out can cause a leak of sensitive info in kernel stack.
Upstream bug:
https://patchwork.ozlabs.org/patch/629100/
Upstream fix:
https://git.kernel.org/cgit/linux/kernel/git/davem/net.git/commit/?id=5d2be1422e02ccd697ccfcd45c85b4a26e6178e2
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1343338]
---
kernel-4.4.13-200.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
---
Bugzilla
CVE-2016-5243 CVE-2016-5244 kernel: various flaws [fedora-all]
bugzilla·2016-06-07·CVSS 5.5
CVE-2016-5243 [MEDIUM] CVE-2016-5243 CVE-2016-5244 kernel: various flaws [fedora-all]
CVE-2016-5243 CVE-2016-5244 kernel: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While o
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=5d2be1422e02ccd697ccfcd45c85b4a26e6178e2http://www.debian.org/security/2016/dsa-3607http://www.openwall.com/lists/oss-security/2016/06/03/4http://www.securityfocus.com/bid/91334http://www.ubuntu.com/usn/USN-3049-1http://www.ubuntu.com/usn/USN-3050-1http://www.ubuntu.com/usn/USN-3051-1http://www.ubuntu.com/usn/USN-3052-1http://www.ubuntu.com/usn/USN-3053-1http://www.ubuntu.com/usn/USN-3054-1http://www.ubuntu.com/usn/USN-3055-1http://www.ubuntu.com/usn/USN-3056-1http://www.ubuntu.com/usn/USN-3057-1https://bugzilla.redhat.com/show_bug.cgi?id=1343335https://github.com/torvalds/linux/commit/5d2be1422e02ccd697ccfcd45c85b4a26e6178e2https://patchwork.ozlabs.org/patch/629100/http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=5d2be1422e02ccd697ccfcd45c85b4a26e6178e2http://www.debian.org/security/2016/dsa-3607http://www.openwall.com/lists/oss-security/2016/06/03/4http://www.securityfocus.com/bid/91334http://www.ubuntu.com/usn/USN-3049-1http://www.ubuntu.com/usn/USN-3050-1http://www.ubuntu.com/usn/USN-3051-1http://www.ubuntu.com/usn/USN-3052-1http://www.ubuntu.com/usn/USN-3053-1http://www.ubuntu.com/usn/USN-3054-1http://www.ubuntu.com/usn/USN-3055-1http://www.ubuntu.com/usn/USN-3056-1http://www.ubuntu.com/usn/USN-3057-1https://bugzilla.redhat.com/show_bug.cgi?id=1343335https://github.com/torvalds/linux/commit/5d2be1422e02ccd697ccfcd45c85b4a26e6178e2https://patchwork.ozlabs.org/patch/629100/
2016-06-27
Published