CVE-2016-3707: High severity linux kernel rt vulnerability
A flaw was found in the kernel-rt in which an attacker could submit a specially crafted ICMP echo request which can trigger a sysrq function based on values in the ICMP packet.
This feature was introduced in the kernel-rt only and is not shipping with standard Red Hat Enterprise Linux kernels.
Remote attacker could exploit this feature using bruteforce to submit arbitrary SysRq commands.
Resources: https://www.kernel.org/pub/linux/kernel/projects/rt/4.4/patch-4.4.7-rt16.patch.gz
Upstream discussion: https://lwn.net/Articles/448790/
CVE request: http://seclists.org/oss-sec/2016/q2/349
Other sources
The icmpchecksysrq function in net/ipv4/icmp.c in the kernel.org projects/rt patches for the Linux kernel, as used in the kernel-rt package before 3.10.0-327.22.1 in Red Hat Enterprise Linux for Real Time 7 and other products, allows remote attackers to execute SysRq commands via crafted ICMP Echo Request packets, as demonstrated by a brute-force attack to discover a cookie, or an attack that occurs after reading the local icmpechosysrq file.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3707?
CVE-2016-3707 has been classified as a moderate severity vulnerability.
How do I fix CVE-2016-3707?
To fix CVE-2016-3707, it is recommended to update the kernel-rt to a version that is higher than 3.10.0.
Who is affected by CVE-2016-3707?
CVE-2016-3707 affects systems running kernel-rt versions up to 3.10.0, specifically Red Hat Enterprise Linux for Real Time and SUSE Linux Enterprise Real Time Extension.
What type of attack does CVE-2016-3707 enable?
CVE-2016-3707 allows an attacker to submit a crafted ICMP echo request, potentially triggering unintended kernel behavior.
Is CVE-2016-3707 present in standard Red Hat kernels?
No, CVE-2016-3707 specifically affects the kernel-rt and is not present in standard Red Hat Enterprise Linux kernels.