CVE-2016-1882: High severity freebsd kernel vulnerability
Published Jan 29, 2016
·Updated
FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9 allow remote attackers to cause a denial of service (kernel crash) via vectors related to creating a TCP connection with the TCPMD5SIG and TCPNOOPT socket options.
Affected Software
3 affected components
FreeBSD FreeBSD=9.3
FreeBSD FreeBSD=10.1
FreeBSD FreeBSD=10.2
Remediation
Event History
Jan 29, 2016
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1882?
CVE-2016-1882 is classified as a denial of service vulnerability which can cause a kernel crash.
2
How do I fix CVE-2016-1882?
To address CVE-2016-1882, it is recommended to apply the latest patches for FreeBSD versions 9.3, 10.1, or 10.2.
3
Which FreeBSD versions are affected by CVE-2016-1882?
CVE-2016-1882 affects FreeBSD versions 9.3 before p33, 10.1 before p26, and 10.2 before p9.
4
What type of attack does CVE-2016-1882 involve?
CVE-2016-1882 involves remote attacks that exploit TCP connection vulnerabilities leading to potential service disruptions.
5
Can CVE-2016-1882 be exploited remotely?
Yes, CVE-2016-1882 allows remote attackers to exploit the vulnerability and cause a denial of service.