CVE-2016-2069: Race Condition
A flaw was discovered in a way the Linux deals with paging structures. When Linux invalidates a paging structure that is not in use locally, it could, in principle, race against another CPU that is switching to a process that uses the paging structure in question.
External reference:
http://seclists.org/oss-sec/2016/q1/194
Upstream fix:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=71b3c126e61177eb693423f2e18a1914205b165e
CVE assignment:
http://seclists.org/oss-sec/2016/q1/210
Other sources
Race condition in arch/x86/mm/tlb.c in the Linux kernel before 4.4.1 allows local users to gain privileges by triggering access to a paging structure by a different CPU.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2016-2069?
CVE-2016-2069 is a vulnerability in the Linux kernel that allows local users to gain privileges through a race condition in the arch/x86/mm/tlb.c file.
How severe is CVE-2016-2069?
CVE-2016-2069 has a severity rating of medium.
Which versions of Linux kernel are affected by CVE-2016-2069?
The affected versions include Linux kernel versions before 4.4.1, 3.2.0-102.142, 3.13.0-87.133, 4.5~, and 4.2.0-30.35.
How can I fix CVE-2016-2069?
To fix CVE-2016-2069, update your Linux kernel to version 4.4.1 or newer.
Where can I find more information about CVE-2016-2069?
You can find more information about CVE-2016-2069 in the references provided: http://www.openwall.com/lists/oss-security/2016/01/25/1, http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=71b3c126e61177eb693423f2e18a1914205b165e, http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.1.