CVE-2016-9754
published 2017-01-05CVE-2016-9754: The ring_buffer_resize function in kernel/trace/ring_buffer.c in the profiling subsystem in the Linux kernel before 4.6.1 mishandles certain integer…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.53%
42.0th percentile
The ring_buffer_resize function in kernel/trace/ring_buffer.c in the profiling subsystem in the Linux kernel before 4.6.1 mishandles certain integer calculations, which allows local users to gain privileges by writing to the /sys/kernel/debug/tracing/buffer_size_kb file.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.6.1-1 (bookworm) | linux 4.6.1-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 4.6.1-1 | 4.6.1-1 |
| linux | linux_kernel | >= 0 < 4.6.1-1 | 4.6.1-1 |
| linux | linux_kernel | >= 0 < 4.6.1-1 | 4.6.1-1 |
| linux | linux_kernel | >= 0 < 4.6.1-1 | 4.6.1-1 |
| linux | linux_kernel | >= 0 < 3.13.0-132.181 | 3.13.0-132.181 |
| linux | linux_kernel | >= 3.11 < 3.12.61 | 3.12.61 |
| linux | linux_kernel | >= 3.13 < 3.14.71 | 3.14.71 |
| linux | linux_kernel | >= 3.15 < 3.16.37 | 3.16.37 |
| linux | linux_kernel | >= 3.17 < 3.18.35 | 3.18.35 |
| linux | linux_kernel | >= 3.19 < 4.1.26 | 4.1.26 |
| linux | linux_kernel | >= 3.5 < 3.10.102 | 3.10.102 |
| linux | linux_kernel | >= 4.2 < 4.4.12 | 4.4.12 |
| linux | linux_kernel | >= 4.5 < 4.5.6 | 4.5.6 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-09-18·CVSS 7.8
CVE-2016-10044 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a buffer overflow existed in the Bluetooth stack of
the Linux kernel when handling L2CAP configuration responses. A physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-2017-1000251)
It was discovered that the asynchronous I/O (aio) subsystem of the Linux
kernel did not properly set permissions on aio memory mappings in some
situations. An attacker could use this to more easily exploit other
vulnerabilities. (CVE-2016-10044)
Baozeng Ding and Andrey Konovalov discovered a race condition in the L2TPv3
IP Encapsulation implementation in the Linux kernel. A local attacker could
use this to cause a denial of service (system cra
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2017-09-18·CVSS 7.8
CVE-2016-10044 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3422-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 LTS.
It was discovered that a buffer overflow existed in the Bluetooth stack of
the Linux kernel when handling L2CAP configuration responses. A physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-2017-1000251)
It was discovered that the asynchronous I/O (aio) subsystem of the Linux
kernel did not properly set permissions on aio memory mappings in some
situations. An attacker could use this to more easily exploit other
vulnerabi
Android
CVE-2016-9754: Android Security Bulletin 2017-01-01
CVE: CVE-2016-9754
Severity: HIGH
References: A-32659848
Upstream kernel
vendor_android·2017-01-01·CVSS 7.8
CVE-2016-9754 [HIGH] CVE-2016-9754: Android Security Bulletin 2017-01-01
CVE: CVE-2016-9754
Severity: HIGH
References: A-32659848
Upstream kernel
Android Security Bulletin 2017-01-01
CVE: CVE-2016-9754
Severity: HIGH
References: A-32659848
Upstream kernel
Red Hat
kernel: Integer overflow in ring_buffer_resize()
vendor_redhat·2016-05-13·CVSS 7.8
CVE-2016-9754 [HIGH] CWE-190 kernel: Integer overflow in ring_buffer_resize()
kernel: Integer overflow in ring_buffer_resize()
The ring_buffer_resize function in kernel/trace/ring_buffer.c in the profiling subsystem in the Linux kernel before 4.6.1 mishandles certain integer calculations, which allows local users to gain privileges by writing to the /sys/kernel/debug/tracing/buffer_size_kb file.
An integer overflow vulnerability was found in the ring_buffer_resize() calculations in which a privileged user can adjust the size of the ringbuffer message size. These calculations can create an issue where the kernel memory allocator will not allocate the correct count of pages yet expect them to be usable. This can lead to the ftrace() output to appear to corrupt kernel memory and possibly be used for privileged escalation or more likely kernel panic.
Statement: This
Debian
CVE-2016-9754: linux - The ring_buffer_resize function in kernel/trace/ring_buffer.c in the profiling s...
vendor_debian·2016·CVSS 7.8
CVE-2016-9754 [HIGH] CVE-2016-9754: linux - The ring_buffer_resize function in kernel/trace/ring_buffer.c in the profiling s...
The ring_buffer_resize function in kernel/trace/ring_buffer.c in the profiling subsystem in the Linux kernel before 4.6.1 mishandles certain integer calculations, which allows local users to gain privileges by writing to the /sys/kernel/debug/tracing/buffer_size_kb file.
Scope: local
bookworm: resolved (fixed in 4.6.1-1)
bullseye: resolved (fixed in 4.6.1-1)
forky: resolved (fixed in 4.6.1-1)
sid: resolved (fixed in 4.6.1-1)
trixie: resolved (fixed in 4.6.1-1)
GHSA
GHSA-795q-99jq-47p3: The ring_buffer_resize function in kernel/trace/ring_buffer
ghsa_unreviewed·2022-05-17
CVE-2016-9754 [HIGH] CWE-190 GHSA-795q-99jq-47p3: The ring_buffer_resize function in kernel/trace/ring_buffer
The ring_buffer_resize function in kernel/trace/ring_buffer.c in the profiling subsystem in the Linux kernel before 4.6.1 mishandles certain integer calculations, which allows local users to gain privileges by writing to the /sys/kernel/debug/tracing/buffer_size_kb file.
OSV
linux vulnerabilities
osv·2017-09-18·CVSS 7.8
CVE-2017-1000251 [HIGH] linux vulnerabilities
linux vulnerabilities
It was discovered that a buffer overflow existed in the Bluetooth stack of
the Linux kernel when handling L2CAP configuration responses. A physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-2017-1000251)
It was discovered that the asynchronous I/O (aio) subsystem of the Linux
kernel did not properly set permissions on aio memory mappings in some
situations. An attacker could use this to more easily exploit other
vulnerabilities. (CVE-2016-10044)
Baozeng Ding and Andrey Konovalov discovered a race condition in the L2TPv3
IP Encapsulation implementation in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2016-10200)
Andreas Gruenbacher an
OSV
CVE-2016-9754: The ring_buffer_resize function in kernel/trace/ring_buffer
osv·2017-01-05·CVSS 7.8
CVE-2016-9754 [HIGH] CVE-2016-9754: The ring_buffer_resize function in kernel/trace/ring_buffer
The ring_buffer_resize function in kernel/trace/ring_buffer.c in the profiling subsystem in the Linux kernel before 4.6.1 mishandles certain integer calculations, which allows local users to gain privileges by writing to the /sys/kernel/debug/tracing/buffer_size_kb file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9754 kernel: Integer overflow in ring_buffer_resize()
bugzilla·2017-01-05·CVSS 7.8
CVE-2016-9754 [HIGH] CVE-2016-9754 kernel: Integer overflow in ring_buffer_resize()
CVE-2016-9754 kernel: Integer overflow in ring_buffer_resize()
An integer overflow vulnerability in ring_buffer_resize() calculations in which a privileged user can adjust the size of the ringbuffer message size. These calculations can create an issue where the kernel memory allocator will not allocate the correct count of pages yet expect them to be usable. This can lead to the ftrace() output to appear to corrupt kernel memory and possibly be used for privileged escalation or more likely kernel panic.
Upstream patch:
https://git.kernel.org/cgit/linux/kernel/git/stable/linux-stable.git/commit/?id=59643d1535eb220668692a5359de22545af579f6
Reference:
https://source.android.com/security/bulletin/2017-01-01.html#eop-in-kernel-profiling-subsystem
Discussion:
Statement:
This issue does n
arXiv
Neural Transfer Learning for Repairing Security Vulnerabilities in C Code
arxiv_fulltext·2022-01-04
Neural Transfer Learning for Repairing Security Vulnerabilities in C Code
Neural Transfer Learning for Repairing
Security Vulnerabilities in C Code
Zimin Chen,
Steve Kommrusch,
and Martin Monperrus
Zimin Chen and Martin Monperrus are with KTH Royal Institute of Technology, Sweden.
E-mail: \zimin, monp\@kth.se
Steve Kommrusch is with Colorado State University, USA.
E-mail: [email protected]
Zimin Chen and Steve Kommrusch have equally contributed to the paper as first authors.
Manuscript submitted 2021-04-16.
## Abstract
In this paper, we address the problem of automatic repair of software vulnerabilities with deep learning. The major problem with data-driven vulnerability repair is that the few existing datasets of known confirmed vulnerabilities consist of only a few thousand examples. However, training a deep learning model often requires hundreds
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=59643d1535eb220668692a5359de22545af579f6http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.6.1http://www.securityfocus.com/bid/95278https://github.com/torvalds/linux/commit/59643d1535eb220668692a5359de22545af579f6https://source.android.com/security/bulletin/2017-01-01.htmlhttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=59643d1535eb220668692a5359de22545af579f6http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.6.1http://www.securityfocus.com/bid/95278https://github.com/torvalds/linux/commit/59643d1535eb220668692a5359de22545af579f6https://source.android.com/security/bulletin/2017-01-01.html
2017-01-05
Published