First published: Fri Jun 24 2016(Updated: )
A vulnerability in the handling of Transactional Memory on powerpc systems was found. An unprivileged local user can crash the kernel by starting a transaction, suspending it, and then calling any of the exec() class system calls. Patch: <a href="https://patchwork.ozlabs.org/patch/636776/">https://patchwork.ozlabs.org/patch/636776/</a> Test case: <a href="https://patchwork.ozlabs.org/patch/636774/">https://patchwork.ozlabs.org/patch/636774/</a> CVE request: <a href="http://seclists.org/oss-sec/2016/q2/595">http://seclists.org/oss-sec/2016/q2/595</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | >=3.9<3.10.103 | |
Linux Linux kernel | >=3.11<3.14.74 | |
Linux Linux kernel | >=3.15<3.16.37 | |
Linux Linux kernel | >=3.17<3.18.37 | |
Linux Linux kernel | >=3.19<4.1.28 | |
Linux Linux kernel | >=4.2<4.4.16 | |
Linux Linux kernel | >=4.6<4.6.5 | |
Novell Suse Linux Enterprise Real Time Extension | =12-sp1 | |
Debian Debian Linux | =8.0 | |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
debian/linux | 5.10.223-1 5.10.226-1 6.1.106-3 6.1.112-1 6.11.4-1 6.11.5-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5828 is a vulnerability in the Linux kernel that affects powerpc platforms and can lead to denial of service or system crash.
CVE-2016-5828 has a severity level of medium.
CVE-2016-5828 affects powerpc platforms.
To fix CVE-2016-5828, update the Linux kernel to version 4.7 or higher.
More information about CVE-2016-5828 can be found at the following references: [link1], [link2], [link3].