CVE-2016-9555
published 2016-11-28CVE-2016-9555: The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows remote…
PriorityP345critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
9.14%
94.7th percentile
The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows remote attackers to cause a denial of service (out-of-bounds slab access) or possibly have unspecified other impact via crafted SCTP data.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.8.11-1 (bookworm) | linux 4.8.11-1 (bookworm) |
| linux | linux_kernel | >= 0 < 4.8.11-1 | 4.8.11-1 |
| linux | linux_kernel | >= 0 < 4.8.11-1 | 4.8.11-1 |
| linux | linux_kernel | >= 0 < 4.8.11-1 | 4.8.11-1 |
| linux | linux_kernel | >= 0 < 4.8.11-1 | 4.8.11-1 |
| linux | linux_kernel | >= 0 < 4.4.0-57.78 | 4.4.0-57.78 |
| linux | linux_kernel | >= 3.11 < 3.12.68 | 3.12.68 |
| linux | linux_kernel | >= 3.13 < 3.16.40 | 3.16.40 |
| linux | linux_kernel | >= 3.17 < 3.18.49 | 3.18.49 |
| linux | linux_kernel | >= 3.19 < 4.4.32 | 4.4.32 |
| linux | linux_kernel | >= 3.2 < 3.2.85 | 3.2.85 |
| linux | linux_kernel | >= 3.3 < 3.10.105 | 3.10.105 |
| linux | linux_kernel | >= 4.5.0 < 4.8.8 | 4.8.8 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2017-02-09·CVSS 9.8
CVE-2016-9555 [CRITICAL] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrey Konovalov discovered that the SCTP implementation in the Linux
kernel improperly handled validation of incoming data. A remote attacker
could use this to cause a denial of service (system crash). (CVE-2016-9555)
It was discovered that multiple memory leaks existed in the XFS
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service (memory consumption). (CVE-2016-9685)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third part
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2017-02-03
CVE-2016-9555 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash if it received specially crafted
network traffic.
Andrey Konovalov discovered that the SCTP implementation in the Linux
kernel improperly handled validation of incoming data. A remote attacker
could use this to cause a denial of service (system crash).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a sta
Ubuntu
Linux kernel (Trusty HWE) vulnerability
vendor_ubuntu·2017-02-03
CVE-2016-9555 Linux kernel (Trusty HWE) vulnerability
Title: Linux kernel (Trusty HWE) vulnerability
Summary: The system could be made to crash if it received specially crafted
network traffic.
USN-3188-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 LTS.
Andrey Konovalov discovered that the SCTP implementation in the Linux
kernel improperly handled validation of incoming data. A remote attacker
could use this to cause a denial of service (system crash).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to rec
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-02-03·CVSS 9.8
CVE-2016-9555 [CRITICAL] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrey Konovalov discovered that the SCTP implementation in the Linux
kernel improperly handled validation of incoming data. A remote attacker
could use this to cause a denial of service (system crash). (CVE-2016-9555)
It was discovered that multiple memory leaks existed in the XFS
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service (memory consumption). (CVE-2016-9685)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2016-12-20·CVSS 5.5
CVE-2015-8964 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
USN-3161-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Tilman Schmidt and Sasha Levin discovered a use-after-free condition in the
TTY implementation in the Linux kernel. A local attacker could use this to
expose sensitive information (kernel memory). (CVE-2015-8964)
It was discovered that the Video For Linux Two (v4l2) implementation in the
Linux kernel did not properly handle multiple planes when processing a
VIDIOC_DQBUF ioctl(). A local attacker could use this to cause a denial of
service (system crash) or possibly execu
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-12-20·CVSS 5.5
CVE-2015-8964 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Tilman Schmidt and Sasha Levin discovered a use-after-free condition in the
TTY implementation in the Linux kernel. A local attacker could use this to
expose sensitive information (kernel memory). (CVE-2015-8964)
It was discovered that the Video For Linux Two (v4l2) implementation in the
Linux kernel did not properly handle multiple planes when processing a
VIDIOC_DQBUF ioctl(). A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2016-4568)
CAI Qian discovered that shared bind mounts in a mount namespace
exponentially added entries without restriction to the Linux kernel's mount
table. A local attacker could use this to cause a
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-12-20·CVSS 4.7
CVE-2016-9313 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
CAI Qian discovered that shared bind mounts in a mount namespace
exponentially added entries without restriction to the Linux kernel's mount
table. A local attacker could use this to cause a denial of service (system
crash). (CVE-2016-6213)
It was discovered that the KVM implementation for x86/x86_64 in the Linux
kernel could dereference a null pointer. An attacker in a guest virtual
machine could use this to cause a denial of service (system crash) in the
KVM host. (CVE-2016-8630)
Eyal Itkin discovered that the IP over IEEE 1394 (FireWire) implementation
in the Linux kernel contained a buffer overflow when handling fragmented
packets. A remote attacker could use this to possibly execute arbi
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2016-12-20·CVSS 5.5
CVE-2015-8964 [MEDIUM] Linux kernel (Raspberry Pi 2) vulnerabilities
Title: Linux kernel (Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Tilman Schmidt and Sasha Levin discovered a use-after-free condition in the
TTY implementation in the Linux kernel. A local attacker could use this to
expose sensitive information (kernel memory). (CVE-2015-8964)
It was discovered that the Video For Linux Two (v4l2) implementation in the
Linux kernel did not properly handle multiple planes when processing a
VIDIOC_DQBUF ioctl(). A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2016-4568)
CAI Qian discovered that shared bind mounts in a mount namespace
exponentially added entries without restriction to the Linux kernel's mount
table. A local attacker could use
Ubuntu
Linux kernel (Qualcomm Snapdragon) vulnerabilities
vendor_ubuntu·2016-12-20·CVSS 5.5
CVE-2015-8964 [MEDIUM] Linux kernel (Qualcomm Snapdragon) vulnerabilities
Title: Linux kernel (Qualcomm Snapdragon) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Tilman Schmidt and Sasha Levin discovered a use-after-free condition in the
TTY implementation in the Linux kernel. A local attacker could use this to
expose sensitive information (kernel memory). (CVE-2015-8964)
It was discovered that the Video For Linux Two (v4l2) implementation in the
Linux kernel did not properly handle multiple planes when processing a
VIDIOC_DQBUF ioctl(). A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2016-4568)
CAI Qian discovered that shared bind mounts in a mount namespace
exponentially added entries without restriction to the Linux kernel's mount
table. A local attacker coul
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2016-12-20·CVSS 4.7
CVE-2016-6213 [MEDIUM] Linux kernel (Raspberry Pi 2) vulnerabilities
Title: Linux kernel (Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
CAI Qian discovered that shared bind mounts in a mount namespace
exponentially added entries without restriction to the Linux kernel's mount
table. A local attacker could use this to cause a denial of service (system
crash). (CVE-2016-6213)
Andreas Gruenbacher and Jan Kara discovered that the filesystem
implementation in the Linux kernel did not clear the setgid bit during a
setxattr call. A local attacker could use this to possibly elevate group
privileges. (CVE-2016-7097)
Marco Grassi discovered that the driver for Areca RAID Controllers in the
Linux kernel did not properly validate control messages. A local attacker
could use this to cause a denial of service (system crash
Red Hat
kernel: Slab out-of-bounds access in sctp_sf_ootb()
vendor_redhat·2016-10-25·CVSS 9.8
CVE-2016-9555 [CRITICAL] CWE-125 kernel: Slab out-of-bounds access in sctp_sf_ootb()
kernel: Slab out-of-bounds access in sctp_sf_ootb()
The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows remote attackers to cause a denial of service (out-of-bounds slab access) or possibly have unspecified other impact via crafted SCTP data.
A flaw was found in the Linux kernel's implementation of the SCTP protocol. A remote attacker could trigger an out-of-bounds read with an offset of up to 64kB potentially causing the system to crash.
Statement: This issue affects the Linux kernels as shipped with Red Hat Enterprise Linux 5, 6, 7, MRG-2 and realtime and will be addressed in future updates.
Package: kernel (Red Hat Enterprise Linux 5) - Affected
Debian
CVE-2016-9555: linux - The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before ...
vendor_debian·2016·CVSS 9.8
CVE-2016-9555 [CRITICAL] CVE-2016-9555: linux - The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before ...
The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows remote attackers to cause a denial of service (out-of-bounds slab access) or possibly have unspecified other impact via crafted SCTP data.
Scope: local
bookworm: resolved (fixed in 4.8.11-1)
bullseye: resolved (fixed in 4.8.11-1)
forky: resolved (fixed in 4.8.11-1)
sid: resolved (fixed in 4.8.11-1)
trixie: resolved (fixed in 4.8.11-1)
GHSA
GHSA-x329-xh53-wmqc: The sctp_sf_ootb function in net/sctp/sm_statefuns
ghsa_unreviewed·2022-05-14
CVE-2016-9555 [CRITICAL] CWE-125 GHSA-x329-xh53-wmqc: The sctp_sf_ootb function in net/sctp/sm_statefuns
The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows remote attackers to cause a denial of service (out-of-bounds slab access) or possibly have unspecified other impact via crafted SCTP data.
OSV
linux-snapdragon vulnerabilities
osv·2016-12-20·CVSS 5.5
CVE-2015-8964 [MEDIUM] linux-snapdragon vulnerabilities
linux-snapdragon vulnerabilities
Tilman Schmidt and Sasha Levin discovered a use-after-free condition in the
TTY implementation in the Linux kernel. A local attacker could use this to
expose sensitive information (kernel memory). (CVE-2015-8964)
It was discovered that the Video For Linux Two (v4l2) implementation in the
Linux kernel did not properly handle multiple planes when processing a
VIDIOC_DQBUF ioctl(). A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2016-4568)
CAI Qian discovered that shared bind mounts in a mount namespace
exponentially added entries without restriction to the Linux kernel's mount
table. A local attacker could use this to cause a denial of service (system
crash). (CVE-2016-6213)
Andreas Grue
OSV
linux vulnerabilities
osv·2016-12-20·CVSS 5.5
CVE-2015-8964 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Tilman Schmidt and Sasha Levin discovered a use-after-free condition in the
TTY implementation in the Linux kernel. A local attacker could use this to
expose sensitive information (kernel memory). (CVE-2015-8964)
It was discovered that the Video For Linux Two (v4l2) implementation in the
Linux kernel did not properly handle multiple planes when processing a
VIDIOC_DQBUF ioctl(). A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2016-4568)
CAI Qian discovered that shared bind mounts in a mount namespace
exponentially added entries without restriction to the Linux kernel's mount
table. A local attacker could use this to cause a denial of service (system
crash). (CVE-2016-6213)
It was discovered that
OSV
linux-lts-xenial vulnerabilities
osv·2016-12-20·CVSS 5.5
CVE-2015-8964 [MEDIUM] linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
USN-3161-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Tilman Schmidt and Sasha Levin discovered a use-after-free condition in the
TTY implementation in the Linux kernel. A local attacker could use this to
expose sensitive information (kernel memory). (CVE-2015-8964)
It was discovered that the Video For Linux Two (v4l2) implementation in the
Linux kernel did not properly handle multiple planes when processing a
VIDIOC_DQBUF ioctl(). A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2016-4568)
CAI Qian discovered that shared bind mou
OSV
linux-raspi2 vulnerabilities
osv·2016-12-20·CVSS 5.5
CVE-2015-8964 [MEDIUM] linux-raspi2 vulnerabilities
linux-raspi2 vulnerabilities
Tilman Schmidt and Sasha Levin discovered a use-after-free condition in the
TTY implementation in the Linux kernel. A local attacker could use this to
expose sensitive information (kernel memory). (CVE-2015-8964)
It was discovered that the Video For Linux Two (v4l2) implementation in the
Linux kernel did not properly handle multiple planes when processing a
VIDIOC_DQBUF ioctl(). A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2016-4568)
CAI Qian discovered that shared bind mounts in a mount namespace
exponentially added entries without restriction to the Linux kernel's mount
table. A local attacker could use this to cause a denial of service (system
crash). (CVE-2016-6213)
Ondrej Kozina di
OSV
CVE-2016-9555: The sctp_sf_ootb function in net/sctp/sm_statefuns
osv·2016-11-28·CVSS 9.8
CVE-2016-9555 [CRITICAL] CVE-2016-9555: The sctp_sf_ootb function in net/sctp/sm_statefuns
The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows remote attackers to cause a denial of service (out-of-bounds slab access) or possibly have unspecified other impact via crafted SCTP data.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9555 kernel: Slab out-of-bounds access in sctp_sf_ootb()
bugzilla·2016-11-23·CVSS 9.8
CVE-2016-9555 [CRITICAL] CVE-2016-9555 kernel: Slab out-of-bounds access in sctp_sf_ootb()
CVE-2016-9555 kernel: Slab out-of-bounds access in sctp_sf_ootb()
A flaw was found in the Linux kernels implementation of sctp protocol in which a remote attacker can trigger an out of bounds read with an offset of up to 64kB. This may panic the machine with a page-fault and the out-of-bounds data does not seem to be returned to the remote attacker.
For this attack to be sucessful, the kernel needs to have both the SCTP protocol module loaded and a process listening as an SCTP server.
Upstream patch:
https://github.com/torvalds/linux/commit/bf911e985d6bbaa328c20c3e05f4eb03de11fdd6
CVE assignment:
http://seclists.org/oss-sec/2016/q4/509
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1397931]
---
This issue was resolved in the 4.8.8 stable releas
Bugzilla
CVE-2016-9555 kernel: Slab out-of-bounds in sctp_sf_ootb() [fedora-all]
bugzilla·2016-11-23·CVSS 9.8
CVE-2016-9555 [CRITICAL] CVE-2016-9555 kernel: Slab out-of-bounds in sctp_sf_ootb() [fedora-all]
CVE-2016-9555 kernel: Slab out-of-bounds in sctp_sf_ootb() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=bf911e985d6bbaa328c20c3e05f4eb03de11fdd6http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00055.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00056.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00067.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00070.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00073.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00076.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00077.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00087.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0086.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0091.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0113.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0307.htmlhttp://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.8.8http://www.openwall.com/lists/oss-security/2016/11/22/18http://www.securityfocus.com/bid/94479http://www.securitytracker.com/id/1037339https://bto.bluecoat.com/security-advisory/sa134https://bugzilla.redhat.com/show_bug.cgi?id=1397930https://github.com/torvalds/linux/commit/bf911e985d6bbaa328c20c3e05f4eb03de11fdd6https://groups.google.com/forum/#%21topic/syzkaller/pAUcHsUJbjkhttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=bf911e985d6bbaa328c20c3e05f4eb03de11fdd6http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00055.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00056.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00067.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00070.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00073.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00076.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00077.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00087.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0086.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0091.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0113.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0307.htmlhttp://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.8.8http://www.openwall.com/lists/oss-security/2016/11/22/18http://www.securityfocus.com/bid/94479http://www.securitytracker.com/id/1037339https://bto.bluecoat.com/security-advisory/sa134https://bugzilla.redhat.com/show_bug.cgi?id=1397930https://github.com/torvalds/linux/commit/bf911e985d6bbaa328c20c3e05f4eb03de11fdd6https://groups.google.com/forum/#%21topic/syzkaller/pAUcHsUJbjk
2016-11-28
Published