CVE-2016-9756
published 2016-12-28CVE-2016-9756: arch/x86/kvm/emulate.c in the Linux kernel before 4.8.12 does not properly initialize Code Segment (CS) in certain error cases, which allows local users to…
PriorityP421medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.44%
36.4th percentile
arch/x86/kvm/emulate.c in the Linux kernel before 4.8.12 does not properly initialize Code Segment (CS) in certain error cases, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.8.15-1 (bookworm) | linux 4.8.15-1 (bookworm) |
| linux | linux_kernel | <= 4.8.11 | — |
| linux | linux_kernel | >= 0 < 4.8.15-1 | 4.8.15-1 |
| linux | linux_kernel | >= 0 < 4.8.15-1 | 4.8.15-1 |
| linux | linux_kernel | >= 0 < 4.8.15-1 | 4.8.15-1 |
| linux | linux_kernel | >= 0 < 4.8.15-1 | 4.8.15-1 |
| linux | linux_kernel | >= 0 < 3.13.0-107.154 | 3.13.0-107.154 |
| linux | linux_kernel | >= 0 < 4.4.0-59.80 | 4.4.0-59.80 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r788-47qv-vw8p: arch/x86/kvm/emulate
ghsa_unreviewed·2022-05-17
CVE-2016-9756 [MEDIUM] CWE-200 GHSA-r788-47qv-vw8p: arch/x86/kvm/emulate
arch/x86/kvm/emulate.c in the Linux kernel before 4.8.12 does not properly initialize Code Segment (CS) in certain error cases, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
OSV
linux vulnerabilities
osv·2017-01-11·CVSS 5.5
CVE-2016-9756 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
did not properly initialize the Code Segment (CS) in certain error cases. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2016-9756)
Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cause a denial of service (system crash or memory
corruption). (CVE-2016-9793)
Baozeng Ding discovered a race condition that could lead to a use-after-
free in the Advanced Linux Sound Architecture (ALSA) subsystem of the Linux
kernel. A local attacker could use this to cause a denial of service
(syste
OSV
linux vulnerabilities
osv·2017-01-11·CVSS 5.5
CVE-2016-9756 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
did not properly initialize the Code Segment (CS) in certain error cases. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2016-9756)
Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cause a denial of service (system crash or memory
corruption). (CVE-2016-9793)
Baozeng Ding discovered a race condition that could lead to a use-after-
free in the Advanced Linux Sound Architecture (ALSA) subsystem of the Linux
kernel. A local attacker could use this to cause a denial of service
(syste
OSV
linux-lts-xenial vulnerabilities
osv·2017-01-11·CVSS 5.5
CVE-2016-9756 [MEDIUM] linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
USN-3169-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
did not properly initialize the Code Segment (CS) in certain error cases. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2016-9756)
Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cause a denial of service (system crash or memory
corruption). (CVE-2016-9793)
OSV
CVE-2016-9756: arch/x86/kvm/emulate
osv·2016-12-28·CVSS 5.5
CVE-2016-9756 [MEDIUM] CVE-2016-9756: arch/x86/kvm/emulate
arch/x86/kvm/emulate.c in the Linux kernel before 4.8.12 does not properly initialize Code Segment (CS) in certain error cases, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-01-11·CVSS 5.5
CVE-2016-9756 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
did not properly initialize the Code Segment (CS) in certain error cases. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2016-9756)
Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cause a denial of service (system crash or memory
corruption). (CVE-2016-9793)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2017-01-11·CVSS 5.5
CVE-2016-9756 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
did not properly initialize the Code Segment (CS) in certain error cases. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2016-9756)
Baozeng Ding discovered a race condition that could lead to a use-after-
free in the Advanced Linux Sound Architecture (ALSA) subsystem of the Linux
kernel. A local attacker could use this to cause a denial of service
(system crash). (CVE-2016-9794)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-01-11·CVSS 5.5
CVE-2016-9756 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
did not properly initialize the Code Segment (CS) in certain error cases. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2016-9756)
Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cause a denial of service (system crash or memory
corruption). (CVE-2016-9793)
Baozeng Ding discovered a race condition that could lead to a use-after-
free in the Advanced Linux Sound Architecture (ALSA) subsystem of the Linux
k
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-01-11·CVSS 5.5
CVE-2016-9756 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
did not properly initialize the Code Segment (CS) in certain error cases. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2016-9756)
Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cause a denial of service (system crash or memory
corruption). (CVE-2016-9793)
Baozeng Ding discovered a race condition that could lead to a use-after-
free in the Advanced Linux Sound Architecture (ALSA) subsystem of the Linux
k
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2017-01-11·CVSS 5.5
CVE-2016-9756 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
USN-3168-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 LTS.
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
did not properly initialize the Code Segment (CS) in certain error cases. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2016-9756)
Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cau
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2017-01-11·CVSS 5.5
CVE-2016-9756 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
USN-3169-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
did not properly initialize the Code Segment (CS) in certain error cases. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2016-9756)
Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cau
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-01-11·CVSS 7.8
CVE-2016-9756 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dmitry Vyukov discovered that the KVM implementation in the Linux
kernel did not properly initialize the Code Segment (CS) in certain
error cases. A local attacker could use this to expose sensitive
information (kernel memory).
Baozeng Ding discovered a race condition that could lead to a use-after-
free in the Advanced Linux Sound Architecture (ALSA) subsystem of the Linux
kernel. A local attacker could use this to cause a denial of service
(system crash). (CVE-2016-9794)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which re
Red Hat
Kernel: kvm: stack memory information leakage
vendor_redhat·2016-11-22·CVSS 5.5
CVE-2016-9756 [MEDIUM] CWE-200 Kernel: kvm: stack memory information leakage
Kernel: kvm: stack memory information leakage
arch/x86/kvm/emulate.c in the Linux kernel before 4.8.12 does not properly initialize Code Segment (CS) in certain error cases, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
Statement: This issue does not affect the versions of the kernel package as shipped with
Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2.
This issue affects the version of Linux kernel as shipped with Red Hat Enterprise
Linux 7.
This has been rated as having Low security impact and is not currently planned
to be addressed in future updates. For additional information, refer to the
Red Hat Enterprise Linux Life Cycle:
-> https://access.redhat.com/support/policy/updates/errata/
Package: kernel (Red H
Debian
CVE-2016-9756: linux - arch/x86/kvm/emulate.c in the Linux kernel before 4.8.12 does not properly initi...
vendor_debian·2016·CVSS 5.5
CVE-2016-9756 [MEDIUM] CVE-2016-9756: linux - arch/x86/kvm/emulate.c in the Linux kernel before 4.8.12 does not properly initi...
arch/x86/kvm/emulate.c in the Linux kernel before 4.8.12 does not properly initialize Code Segment (CS) in certain error cases, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
Scope: local
bookworm: resolved (fixed in 4.8.15-1)
bullseye: resolved (fixed in 4.8.15-1)
forky: resolved (fixed in 4.8.15-1)
sid: resolved (fixed in 4.8.15-1)
trixie: resolved (fixed in 4.8.15-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9756 Kernel: kvm: stack memory information leakage
bugzilla·2016-12-01·CVSS 5.5
CVE-2016-9756 [MEDIUM] CVE-2016-9756 Kernel: kvm: stack memory information leakage
CVE-2016-9756 Kernel: kvm: stack memory information leakage
Linux kernel built with the Kernel-based Virtual Machine(CONFIG_KVM) support
is vulnerable to an information leakage issue. It could occur on x86 platform,
while emulating instructions in 32bit mode.
A user/process could use this flaw to leak host kernel memory bytes.
Upstream patch:
-> https://git.kernel.org/linus/2117d5398c81554fbf803f5fd1dc55eb78216c0c
Reference:
-> http://www.openwall.com/lists/oss-security/2016/12/01/1
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1400469]
---
Statement:
This issue does not affect the versions of the kernel package as shipped with
Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2.
This issue affects the version of Linux kernel as shipped
Bugzilla
CVE-2016-9756 Kernel: kvm: stack memory information leakage [fedora-all]
bugzilla·2016-12-01·CVSS 5.5
CVE-2016-9756 [MEDIUM] CVE-2016-9756 Kernel: kvm: stack memory information leakage [fedora-all]
CVE-2016-9756 Kernel: kvm: stack memory information leakage [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedor
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2117d5398c81554fbf803f5fd1dc55eb78216c0chttp://lists.opensuse.org/opensuse-security-announce/2017-01/msg00000.htmlhttp://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.8.12http://www.openwall.com/lists/oss-security/2016/12/01/1http://www.securityfocus.com/bid/94615https://bugzilla.redhat.com/show_bug.cgi?id=1400468https://github.com/torvalds/linux/commit/2117d5398c81554fbf803f5fd1dc55eb78216c0chttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2117d5398c81554fbf803f5fd1dc55eb78216c0chttp://lists.opensuse.org/opensuse-security-announce/2017-01/msg00000.htmlhttp://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.8.12http://www.openwall.com/lists/oss-security/2016/12/01/1http://www.securityfocus.com/bid/94615https://bugzilla.redhat.com/show_bug.cgi?id=1400468https://github.com/torvalds/linux/commit/2117d5398c81554fbf803f5fd1dc55eb78216c0c
2016-12-28
Published