CVE-2016-9806
published 2016-12-28CVE-2016-9806: Race condition in the netlink_dump function in net/netlink/af_netlink.c in the Linux kernel before 4.6.3 allows local users to cause a denial of service…
PriorityP434high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.36%
29.2th percentile
Race condition in the netlink_dump function in net/netlink/af_netlink.c in the Linux kernel before 4.6.3 allows local users to cause a denial of service (double free) or possibly have unspecified other impact via a crafted application that makes sendmsg system calls, leading to a free operation associated with a new dump that started earlier than anticipated.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.6.3-1 (bookworm) | linux 4.6.3-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | >= 0 < 4.6.3-1 | 4.6.3-1 |
| linux | linux_kernel | >= 0 < 4.6.3-1 | 4.6.3-1 |
| linux | linux_kernel | >= 0 < 4.6.3-1 | 4.6.3-1 |
| linux | linux_kernel | >= 0 < 4.6.3-1 | 4.6.3-1 |
| linux | linux_kernel | >= 0 < 3.13.0-107.154 | 3.13.0-107.154 |
| linux | linux_kernel | >= 3.12 < 3.12.62 | 3.12.62 |
| linux | linux_kernel | >= 3.13 < 3.14.73 | 3.14.73 |
| linux | linux_kernel | >= 3.15 < 3.16.37 | 3.16.37 |
| linux | linux_kernel | >= 3.17 < 3.18.37 | 3.18.37 |
| linux | linux_kernel | >= 3.19 < 4.1.28 | 4.1.28 |
| linux | linux_kernel | >= 4.2 < 4.4.14 | 4.4.14 |
| linux | linux_kernel | >= 4.5 < 4.6.3 | 4.6.3 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2016-9806: Android Security Bulletin 2017-03-01
CVE: CVE-2016-9806
Severity: CRITICAL
References: A-33393474
Upstream kernel
vendor_android·2017-03-01·CVSS 7.8
CVE-2016-9806 [HIGH] CVE-2016-9806: Android Security Bulletin 2017-03-01
CVE: CVE-2016-9806
Severity: CRITICAL
References: A-33393474
Upstream kernel
Android Security Bulletin 2017-03-01
CVE: CVE-2016-9806
Severity: CRITICAL
References: A-33393474
Upstream kernel
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-01-11·CVSS 5.5
CVE-2016-9756 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
did not properly initialize the Code Segment (CS) in certain error cases. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2016-9756)
Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cause a denial of service (system crash or memory
corruption). (CVE-2016-9793)
Baozeng Ding discovered a race condition that could lead to a use-after-
free in the Advanced Linux Sound Architecture (ALSA) subsystem of the Linux
k
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2017-01-11·CVSS 5.5
CVE-2016-9756 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
USN-3168-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 LTS.
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
did not properly initialize the Code Segment (CS) in certain error cases. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2016-9756)
Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cau
Red Hat
kernel: netlink: double-free in netlink_dump
vendor_redhat·2016-05-15·CVSS 7.8
CVE-2016-9806 [HIGH] CWE-416 kernel: netlink: double-free in netlink_dump
kernel: netlink: double-free in netlink_dump
Race condition in the netlink_dump function in net/netlink/af_netlink.c in the Linux kernel before 4.6.3 allows local users to cause a denial of service (double free) or possibly have unspecified other impact via a crafted application that makes sendmsg system calls, leading to a free operation associated with a new dump that started earlier than anticipated.
A double free vulnerability was found in netlink_dump, which could cause a denial of service or possibly other unspecified impact. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6 as the code with the flaw is not p
Debian
CVE-2016-9806: linux - Race condition in the netlink_dump function in net/netlink/af_netlink.c in the L...
vendor_debian·2016·CVSS 7.8
CVE-2016-9806 [HIGH] CVE-2016-9806: linux - Race condition in the netlink_dump function in net/netlink/af_netlink.c in the L...
Race condition in the netlink_dump function in net/netlink/af_netlink.c in the Linux kernel before 4.6.3 allows local users to cause a denial of service (double free) or possibly have unspecified other impact via a crafted application that makes sendmsg system calls, leading to a free operation associated with a new dump that started earlier than anticipated.
Scope: local
bookworm: resolved (fixed in 4.6.3-1)
bullseye: resolved (fixed in 4.6.3-1)
forky: resolved (fixed in 4.6.3-1)
sid: resolved (fixed in 4.6.3-1)
trixie: resolved (fixed in 4.6.3-1)
GHSA
GHSA-3fhq-qffp-rp75: Race condition in the netlink_dump function in net/netlink/af_netlink
ghsa_unreviewed·2022-05-14
CVE-2016-9806 [HIGH] CWE-362 GHSA-3fhq-qffp-rp75: Race condition in the netlink_dump function in net/netlink/af_netlink
Race condition in the netlink_dump function in net/netlink/af_netlink.c in the Linux kernel before 4.6.3 allows local users to cause a denial of service (double free) or possibly have unspecified other impact via a crafted application that makes sendmsg system calls, leading to a free operation associated with a new dump that started earlier than anticipated.
OSV
linux vulnerabilities
osv·2017-01-11·CVSS 5.5
CVE-2016-9756 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
did not properly initialize the Code Segment (CS) in certain error cases. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2016-9756)
Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cause a denial of service (system crash or memory
corruption). (CVE-2016-9793)
Baozeng Ding discovered a race condition that could lead to a use-after-
free in the Advanced Linux Sound Architecture (ALSA) subsystem of the Linux
kernel. A local attacker could use this to cause a denial of service
(syste
OSV
CVE-2016-9806: Race condition in the netlink_dump function in net/netlink/af_netlink
osv·2016-12-28·CVSS 7.8
CVE-2016-9806 [HIGH] CVE-2016-9806: Race condition in the netlink_dump function in net/netlink/af_netlink
Race condition in the netlink_dump function in net/netlink/af_netlink.c in the Linux kernel before 4.6.3 allows local users to cause a denial of service (double free) or possibly have unspecified other impact via a crafted application that makes sendmsg system calls, leading to a free operation associated with a new dump that started earlier than anticipated.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9806 kernel: netlink: double-free in netlink_dump
bugzilla·2016-12-05·CVSS 7.8
CVE-2016-9806 [HIGH] CVE-2016-9806 kernel: netlink: double-free in netlink_dump
CVE-2016-9806 kernel: netlink: double-free in netlink_dump
A double free vulnerability was found in netlink_dump, which could cause a denial of service or possibly other unspecified impact.
References:
http://seclists.org/oss-sec/2016/q4/577
http://lists.openwall.net/netdev/2016/05/15/69
Upstream patch:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=92964c79b357efd980812c4de5c1fd2ec8bb5520
Discussion:
Statement:
This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6 as the code with the flaw is not present in the products listed.
This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 7 and Red Hat Enterprise MRG-2. Future Linux kernel updates for the respective releases might ad
Bugzilla
CVE-2014-9806 ImageMagick: fd leak due to corrupted file
bugzilla·2016-06-07·CVSS 5.5
CVE-2014-9806 [MEDIUM] CVE-2014-9806 ImageMagick: fd leak due to corrupted file
CVE-2014-9806 ImageMagick: fd leak due to corrupted file
Do not leak fd due to corrupted file.
CVE assignment:
http://seclists.org/oss-sec/2016/q2/459
Most probable upstream patch:
https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=44675e8e48977bbeb1cafade861db2d777a5c7ae
Discussion:
I htink it is probably this one:
https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=9fdb9bf2832a1aa2c79002ae5c2ba1e8018e4ff1
as it has:
Added missing calls to RelinquishUniqueFileResource.
Avoid to leak fd in case of error.
arXiv
A Context-Sensitive, Outlier-Based Static Analysis to Find Kernel Race Conditions
arxiv_fulltext·2024-03-30
A Context-Sensitive, Outlier-Based Static Analysis to Find Kernel Race Conditions
A Context-Sensitive, Outlier-Based Static Analysis to Find Kernel Race Conditions
Niels Dossche
Ghent University
Bert Abrath
Ghent University
Bart Coppens
Ghent University
* [1][1ex]
-0.5ex 0.5ex 0 0
* [1][1ex]
-0.5ex 0.5ex 0 0
* [1][1ex]
0 0.5ex 0 0
* [1][1ex]
* [1][1ex]
* [1][1ex]
1mm
bccnt
[1]bccnt
magentaBart [ ]: #1
bacnt
[1]bacnt
blueBert [ ]: #1
ndcnt
carrotorangergb0.93, 0.57, 0.13
[1]ndcnt
carrotorangeNiels [ ]: #1
LLIF
[1]round(#1, 2) (floor(100*#1) == 100*#1) ? 0 : 9 0.00
[2]
#1#2
[1]100 * #1falsepositives / (#1truepositives + #1falsepositives)%
1214
24
23
1107
211
648
248
modulesandcorenoheuristics
611
257
169
185
modulesandcoreallheuristics
0.10%
1 minute and 3 seconds
56 seconds
49 seconds
8 minutes and 59 seconds
5 minutes and 42 seconds
mygreenrgb0,
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=92964c79b357efd980812c4de5c1fd2ec8bb5520http://lists.openwall.net/netdev/2016/05/15/69http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.6.3http://www.openwall.com/lists/oss-security/2016/12/03/4http://www.securityfocus.com/bid/94653http://www.securitytracker.com/id/1037968https://access.redhat.com/errata/RHSA-2017:1842https://access.redhat.com/errata/RHSA-2017:2077https://access.redhat.com/errata/RHSA-2017:2669https://bugzilla.redhat.com/show_bug.cgi?id=1401502https://github.com/torvalds/linux/commit/92964c79b357efd980812c4de5c1fd2ec8bb5520https://source.android.com/security/bulletin/2017-03-01.htmlhttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=92964c79b357efd980812c4de5c1fd2ec8bb5520http://lists.openwall.net/netdev/2016/05/15/69http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.6.3http://www.openwall.com/lists/oss-security/2016/12/03/4http://www.securityfocus.com/bid/94653http://www.securitytracker.com/id/1037968https://access.redhat.com/errata/RHSA-2017:1842https://access.redhat.com/errata/RHSA-2017:2077https://access.redhat.com/errata/RHSA-2017:2669https://bugzilla.redhat.com/show_bug.cgi?id=1401502https://github.com/torvalds/linux/commit/92964c79b357efd980812c4de5c1fd2ec8bb5520https://source.android.com/security/bulletin/2017-03-01.html
2016-12-28
Published