CVE-2016-5828
published 2016-06-27CVE-2016-5828: The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, which allows…
PriorityP434high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.45%
36.5th percentile
The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, which allows local users to cause a denial of service (invalid process state or TM Bad Thing exception, and system crash) or possibly have unspecified other impact by starting and suspending a transaction before an exec system call.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.6.3-1 (bookworm) | linux 4.6.3-1 (bookworm) |
| linux | linux_kernel | >= 0 < 4.6.3-1 | 4.6.3-1 |
| linux | linux_kernel | >= 0 < 4.6.3-1 | 4.6.3-1 |
| linux | linux_kernel | >= 0 < 4.6.3-1 | 4.6.3-1 |
| linux | linux_kernel | >= 0 < 4.6.3-1 | 4.6.3-1 |
| linux | linux_kernel | >= 0 < 3.13.0-95.142 | 3.13.0-95.142 |
| linux | linux_kernel | >= 0 < 4.4.0-36.55 | 4.4.0-36.55 |
| linux | linux_kernel | >= 3.11 < 3.14.74 | 3.14.74 |
| linux | linux_kernel | >= 3.15 < 3.16.37 | 3.16.37 |
| linux | linux_kernel | >= 3.17 < 3.18.37 | 3.18.37 |
| linux | linux_kernel | >= 3.19 < 4.1.28 | 4.1.28 |
| linux | linux_kernel | >= 3.9 < 3.10.103 | 3.10.103 |
| linux | linux_kernel | >= 4.2 < 4.4.16 | 4.4.16 |
| linux | linux_kernel | >= 4.6 < 4.6.5 | 4.6.5 |
| novell | suse_linux_enterprise_real_time_extension | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2016-08-30·CVSS 5.5
CVE-2016-1237 [MEDIUM] Linux kernel (Raspberry Pi 2) vulnerabilities
Title: Linux kernel (Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
James Patrick-Evans discovered that the airspy USB device driver in the
Linux kernel did not properly handle certain error conditions. An attacker
with physical access could use this to cause a denial of service (memory
consumption). (CVE-2016-5400)
Yue Cao et al discovered a flaw in
Ubuntu
Linux kernel (Qualcomm Snapdragon) vulnerabilities
vendor_ubuntu·2016-08-30·CVSS 5.5
CVE-2016-1237 [MEDIUM] Linux kernel (Qualcomm Snapdragon) vulnerabilities
Title: Linux kernel (Qualcomm Snapdragon) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
James Patrick-Evans discovered that the airspy USB device driver in the
Linux kernel did not properly handle certain error conditions. An attacker
with physical access could use this to cause a denial of service (memory
consumption). (CVE-2016-5400)
Yue Cao et al discovered a fla
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2016-08-30·CVSS 5.5
CVE-2016-1237 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
USN-3070-1 fixed vulnerabilities in the Linux kernel for Ubuntu
16.04 LTS. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for
Ubuntu 14.04 LTS.
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
James Patrick-Evans discovered that the airspy USB device driver in the
Linu
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-08-29·CVSS 7.5
CVE-2016-5244 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
Yue Cao et al discovered a flaw in the TCP implementation's handling of
challenge acks in the Linux kernel. A remote attacker could use this to
cause a denial of service (reset connection) or inject content into an TCP
stream. (CVE-2016-5696)
Pengfei Wang discovered a race condition in the MIC VOP driver in the Linux
kernel. A local attacker could use this to cause a denial of service
(system crash) or obtain potentially sensitive information from kernel
memory. (CVE-
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-08-29·CVSS 5.5
CVE-2016-1237 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
James Patrick-Evans discovered that the airspy USB device driver in the
Linux kernel did not properly handle certain error conditions. An attacker
with physical access could use this to cause a denial of service (memory
consumption). (CVE-2016-5400)
Yue Cao et al discovered a flaw in the TCP implement
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2016-08-29·CVSS 7.5
CVE-2016-5244 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
USN-3071-1 fixed vulnerabilities in the Linux kernel for Ubuntu
14.04 LTS. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for
Ubuntu 12.04 LTS.
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
Yue Cao et al discovered a flaw in the TCP implementation's handling of
challenge acks in the Linux kernel. A remote attacker could use this to
cause a denial of service (reset connection) or inject content into an TCP
stream. (CVE-2016-5696)
Pe
Red Hat
Kernel: powerpc: tm: crash via exec system call on PPC
vendor_redhat·2016-06-24·CVSS 7.8
CVE-2016-5828 [HIGH] Kernel: powerpc: tm: crash via exec system call on PPC
Kernel: powerpc: tm: crash via exec system call on PPC
The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, which allows local users to cause a denial of service (invalid process state or TM Bad Thing exception, and system crash) or possibly have unspecified other impact by starting and suspending a transaction before an exec system call.
A vulnerability in the handling of Transactional Memory on powerpc systems was found. An unprivileged local user can crash the kernel by starting a transaction, suspending it, and then calling any of the exec() class system calls.
Statement: This issue does not affect the versions of Linux kernel as shipped with
Red Hat Enterprise Linux 5, 6 and Red Hat Enterpr
Debian
CVE-2016-5828: linux - The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel t...
vendor_debian·2016·CVSS 7.8
CVE-2016-5828 [HIGH] CVE-2016-5828: linux - The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel t...
The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, which allows local users to cause a denial of service (invalid process state or TM Bad Thing exception, and system crash) or possibly have unspecified other impact by starting and suspending a transaction before an exec system call.
Scope: local
bookworm: resolved (fixed in 4.6.3-1)
bullseye: resolved (fixed in 4.6.3-1)
forky: resolved (fixed in 4.6.3-1)
sid: resolved (fixed in 4.6.3-1)
trixie: resolved (fixed in 4.6.3-1)
GHSA
GHSA-64c3-3r62-5c6c: The start_thread function in arch/powerpc/kernel/process
ghsa_unreviewed·2022-05-14
CVE-2016-5828 [HIGH] CWE-20 GHSA-64c3-3r62-5c6c: The start_thread function in arch/powerpc/kernel/process
The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, which allows local users to cause a denial of service (invalid process state or TM Bad Thing exception, and system crash) or possibly have unspecified other impact by starting and suspending a transaction before an exec system call.
OSV
linux-lts-xenial vulnerabilities
osv·2016-08-30·CVSS 5.5
CVE-2016-1237 [MEDIUM] linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
USN-3070-1 fixed vulnerabilities in the Linux kernel for Ubuntu
16.04 LTS. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for
Ubuntu 14.04 LTS.
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
James Patrick-Evans discovered that the airspy USB device driver in the
Linux kernel did not properly handle certain error conditions. An attacker
with
OSV
linux-snapdragon vulnerabilities
osv·2016-08-30·CVSS 5.5
CVE-2016-1237 [MEDIUM] linux-snapdragon vulnerabilities
linux-snapdragon vulnerabilities
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
James Patrick-Evans discovered that the airspy USB device driver in the
Linux kernel did not properly handle certain error conditions. An attacker
with physical access could use this to cause a denial of service (memory
consumption). (CVE-2016-5400)
Yue Cao et al discovered a flaw in the TCP implementation's handling of
challenge acks in the Linux kernel. A remot
OSV
linux-raspi2 vulnerabilities
osv·2016-08-30·CVSS 5.5
CVE-2016-1237 [MEDIUM] linux-raspi2 vulnerabilities
linux-raspi2 vulnerabilities
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
James Patrick-Evans discovered that the airspy USB device driver in the
Linux kernel did not properly handle certain error conditions. An attacker
with physical access could use this to cause a denial of service (memory
consumption). (CVE-2016-5400)
Yue Cao et al discovered a flaw in the TCP implementation's handling of
challenge acks in the Linux kernel. A remote at
OSV
linux vulnerabilities
osv·2016-08-29·CVSS 7.5
CVE-2016-5244 [HIGH] linux vulnerabilities
linux vulnerabilities
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
Yue Cao et al discovered a flaw in the TCP implementation's handling of
challenge acks in the Linux kernel. A remote attacker could use this to
cause a denial of service (reset connection) or inject content into an TCP
stream. (CVE-2016-5696)
Pengfei Wang discovered a race condition in the MIC VOP driver in the Linux
kernel. A local attacker could use this to cause a denial of service
(system crash) or obtain potentially sensitive information from kernel
memory. (CVE-2016-5728)
Cyril Bur discovered that on PowerPC platforms, the Linux kern
OSV
linux vulnerabilities
osv·2016-08-29·CVSS 5.5
CVE-2016-1237 [MEDIUM] linux vulnerabilities
linux vulnerabilities
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
James Patrick-Evans discovered that the airspy USB device driver in the
Linux kernel did not properly handle certain error conditions. An attacker
with physical access could use this to cause a denial of service (memory
consumption). (CVE-2016-5400)
Yue Cao et al discovered a flaw in the TCP implementation's handling of
challenge acks in the Linux kernel. A remote attacker
OSV
CVE-2016-5828: The start_thread function in arch/powerpc/kernel/process
osv·2016-06-27·CVSS 7.8
CVE-2016-5828 [HIGH] CVE-2016-5828: The start_thread function in arch/powerpc/kernel/process
The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, which allows local users to cause a denial of service (invalid process state or TM Bad Thing exception, and system crash) or possibly have unspecified other impact by starting and suspending a transaction before an exec system call.
Kernel
powerpc/tm: Always reclaim in start_thread() for exec() class syscalls
kernel_security·2016-06-17
CVE-2016-5828 powerpc/tm: Always reclaim in start_thread() for exec() class syscalls
powerpc/tm: Always reclaim in start_thread() for exec() class syscalls
Userspace can quite legitimately perform an exec() syscall with a
suspended transaction. exec() does not return to the old process, rather
it load a new one and starts that, the expectation therefore is that the
new process starts not in a transaction. Currently exec() is not treated
any differently to any other syscall which creates problems.
Firstly it could allow a new process to start with a suspended
transaction for a binary that no longer exists. This means that the
checkpointed state won't be valid and if the suspended transaction were
ever to be resumed and subsequently aborted (a possibility which is
exceedingly likely as exec()ing will likely doom the transaction) the
new process will jump to invalid state.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-5828 Kernel: powerpc: tm: crash via exec system call on PPC [fedora-all]
bugzilla·2016-07-28·CVSS 7.8
CVE-2016-5828 [HIGH] CVE-2016-5828 Kernel: powerpc: tm: crash via exec system call on PPC [fedora-all]
CVE-2016-5828 Kernel: powerpc: tm: crash via exec system call on PPC [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2016-5828 Kernel: powerpc: tm: crash via exec system call on PPC
bugzilla·2016-06-24·CVSS 7.8
CVE-2016-5828 [HIGH] CVE-2016-5828 Kernel: powerpc: tm: crash via exec system call on PPC
CVE-2016-5828 Kernel: powerpc: tm: crash via exec system call on PPC
A vulnerability in the handling of Transactional Memory on powerpc systems was found. An unprivileged local user can crash the kernel by starting a transaction, suspending it, and then calling any of the exec() class system calls.
Patch:
https://patchwork.ozlabs.org/patch/636776/
Test case:
https://patchwork.ozlabs.org/patch/636774/
CVE request:
http://seclists.org/oss-sec/2016/q2/595
Discussion:
Created xen tracking bugs for this issue:
Affects: fedora-all [bug 1349919]
---
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1349918]
---
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1361109]
---
Statement:
This issue does not affect the versions of Linux kernel a
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2574.htmlhttp://www.debian.org/security/2016/dsa-3616http://www.openwall.com/lists/oss-security/2016/06/25/7http://www.securityfocus.com/bid/91415http://www.ubuntu.com/usn/USN-3070-1http://www.ubuntu.com/usn/USN-3070-2http://www.ubuntu.com/usn/USN-3070-3http://www.ubuntu.com/usn/USN-3070-4http://www.ubuntu.com/usn/USN-3071-1http://www.ubuntu.com/usn/USN-3071-2https://patchwork.ozlabs.org/patch/636776/http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2574.htmlhttp://www.debian.org/security/2016/dsa-3616http://www.openwall.com/lists/oss-security/2016/06/25/7http://www.securityfocus.com/bid/91415http://www.ubuntu.com/usn/USN-3070-1http://www.ubuntu.com/usn/USN-3070-2http://www.ubuntu.com/usn/USN-3070-3http://www.ubuntu.com/usn/USN-3070-4http://www.ubuntu.com/usn/USN-3071-1http://www.ubuntu.com/usn/USN-3071-2https://patchwork.ozlabs.org/patch/636776/
2016-06-27
Published