CVE-2016-9919
published 2016-12-08CVE-2016-9919: The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 omits a certain check of the dst data structure, which allows remote attackers to…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
5.67%
92.1th percentile
The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 omits a certain check of the dst data structure, which allows remote attackers to cause a denial of service (panic) via a fragmented IPv6 packet.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.8.15-1 (bookworm) | linux 4.8.15-1 (bookworm) |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 4.8.15-1 | 4.8.15-1 |
| linux | linux_kernel | >= 0 < 4.8.15-1 | 4.8.15-1 |
| linux | linux_kernel | >= 0 < 4.8.15-1 | 4.8.15-1 |
| linux | linux_kernel | >= 0 < 4.8.15-1 | 4.8.15-1 |
| linux | linux_kernel | >= 4.8.10 < 4.9 | 4.9 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2017-01-11·CVSS 7.8
CVE-2016-9793 [HIGH] Linux kernel (Raspberry Pi 2) vulnerabilities
Title: Linux kernel (Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrey Konovalov discovered that the ipv6 icmp implementation in the Linux
kernel did not properly check data structures on send. A remote attacker
could use this to cause a denial of service (system crash). (CVE-2016-9919)
Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cause a denial of service (system crash or memory
corruption). (CVE-2016-9793)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI ch
Red Hat
kernel: Linux panic on fragemented IPv6 traffic (icmp6_send)
vendor_redhat·2016-12-08·CVSS 7.5
CVE-2016-9919 [HIGH] CWE-20 kernel: Linux panic on fragemented IPv6 traffic (icmp6_send)
kernel: Linux panic on fragemented IPv6 traffic (icmp6_send)
The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 omits a certain check of the dst data structure, which allows remote attackers to cause a denial of service (panic) via a fragmented IPv6 packet.
The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 omits a certain check of the dst data structure which allows remote attackers to cause a denial of service (panic) via a fragmented IPv6 packet.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG-2 as the code with the flaw is not present in the products listed.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red
Debian
CVE-2016-9919: linux - The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 om...
vendor_debian·2016·CVSS 7.5
CVE-2016-9919 [HIGH] CVE-2016-9919: linux - The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 om...
The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 omits a certain check of the dst data structure, which allows remote attackers to cause a denial of service (panic) via a fragmented IPv6 packet.
Scope: local
bookworm: resolved (fixed in 4.8.15-1)
bullseye: resolved (fixed in 4.8.15-1)
forky: resolved (fixed in 4.8.15-1)
sid: resolved (fixed in 4.8.15-1)
trixie: resolved (fixed in 4.8.15-1)
GHSA
GHSA-952c-5r47-vpqf: The icmp6_send function in net/ipv6/icmp
ghsa_unreviewed·2022-05-17
CVE-2016-9919 [HIGH] CWE-20 GHSA-952c-5r47-vpqf: The icmp6_send function in net/ipv6/icmp
The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 omits a certain check of the dst data structure, which allows remote attackers to cause a denial of service (panic) via a fragmented IPv6 packet.
OSV
CVE-2016-9919: The icmp6_send function in net/ipv6/icmp
osv·2016-12-08·CVSS 7.5
CVE-2016-9919 [HIGH] CVE-2016-9919: The icmp6_send function in net/ipv6/icmp
The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 omits a certain check of the dst data structure, which allows remote attackers to cause a denial of service (panic) via a fragmented IPv6 packet.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9919 kernel: Linux panic on fragemented IPv6 traffic (icmp6_send) [fedora-all]
bugzilla·2016-12-09·CVSS 7.5
CVE-2016-9919 [HIGH] CVE-2016-9919 kernel: Linux panic on fragemented IPv6 traffic (icmp6_send) [fedora-all]
CVE-2016-9919 kernel: Linux panic on fragemented IPv6 traffic (icmp6_send) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2016-9919 kernel: Linux panic on fragemented IPv6 traffic (icmp6_send)
bugzilla·2016-12-09·CVSS 7.5
CVE-2016-9919 [HIGH] CVE-2016-9919 kernel: Linux panic on fragemented IPv6 traffic (icmp6_send)
CVE-2016-9919 kernel: Linux panic on fragemented IPv6 traffic (icmp6_send)
The linux kernel contains a bug where a fragmented IPv6 packet causes a panic after a timeout (seems to be roughly 60 seconds). This can be triggered remotely via the internet and results in a DoS (kernel panic). The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 omits a certain check of the dst data structure, which allows remote attackers to cause a denial of service (panic) via a fragmented IPv6 packet.
Upstream bug:
https://bugzilla.kernel.org/show_bug.cgi?id=189851
Upstream patches:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=79dc7e3f1c
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=5d41ce29e3
http://git.kernel.org/cgit/l
arXiv
KASR: A Reliable and Practical Approach to Attack Surface Reduction of Commodity OS Kernels
arxiv_fulltext·2018-11-29
KASR: A Reliable and Practical Approach to Attack Surface Reduction of Commodity OS Kernels
[1]2pt#1.
KASR
[1]
[3]#3#1 says: #2
[1]zhi#1blue
: A Reliable and Practical Approach to Attack Surface Reduction of
Commodity OS Kernels
A Reliable and Practical Approach to Kernel Attack Surface Reduction
Zhi Zhang1,2( )
Yueqiang Cheng3
Surya Nepal1
Dongxi Liu1
Qingni Shen4
Fethi Rabhi2
Z. Zhang et al.
Data61, CSIRO, Australia
\zhi.zhang,surya.nepal,dongxi.liu\@data61.csiro.au
University of New South Wales, Sydney, Australia
[email protected], [email protected]
Baidu XLab, Sunnyvale, California, United States
[email protected]
Peking University, Beijing, China
[email protected]
empty
## Abstract
Commodity OS kernels have broad attack surfaces due to the large code base and the numerous features such as device drivers. For a real-world use case (e.g
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=79dc7e3f1cd323be4c81aa1a94faa1b3ed987fb2http://www.openwall.com/lists/oss-security/2016/12/08/15http://www.securityfocus.com/bid/94824https://github.com/torvalds/linux/commit/79dc7e3f1cd323be4c81aa1a94faa1b3ed987fb2http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=79dc7e3f1cd323be4c81aa1a94faa1b3ed987fb2http://www.openwall.com/lists/oss-security/2016/12/08/15http://www.securityfocus.com/bid/94824https://github.com/torvalds/linux/commit/79dc7e3f1cd323be4c81aa1a94faa1b3ed987fb2
2016-12-08
Published