CVE-2016-6187: Buffer Overflow
A vulnerability leading to a local privilege escalation was found in apparmor in the Linux kernel. When procpidattrwrite() was changed to use memdupuser apparmor's (interface violating) assumption that the setprocattr buffer was always a single page was violated.
Upstream pull request:
http://marc.info/?l=linux-kernel&m=146793642811929&w=2
Upstream fix:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=30a46a4647fd1df9cf52e43bf467f0d9265096ca
References:
http://seclists.org/oss-sec/2016/q3/30
Other sources
The apparmorsetprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buffer size, which allows local users to gain privileges by triggering an AppArmor setprocattr hook.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6187?
CVE-2016-6187 has a high severity rating due to its potential for local privilege escalation.
How do I fix CVE-2016-6187?
To mitigate CVE-2016-6187, users should update their Linux kernel to version 4.6.5 or later.
What systems are affected by CVE-2016-6187?
CVE-2016-6187 affects the Linux kernel versions between 4.5 and 4.6.5.
What type of vulnerability is CVE-2016-6187?
CVE-2016-6187 is categorized as a local privilege escalation vulnerability.
What causes CVE-2016-6187?
CVE-2016-6187 is caused by an assumption violation in apparmor related to the setprocattr buffer handling.