CWE
119
Advisory Published

USN-3162-1: Linux kernel vulnerabilities

First published: Tue Dec 20 2016(Updated: )

CAI Qian discovered that shared bind mounts in a mount namespace exponentially added entries without restriction to the Linux kernel's mount table. A local attacker could use this to cause a denial of service (system crash). (CVE-2016-6213) It was discovered that the KVM implementation for x86/x86_64 in the Linux kernel could dereference a null pointer. An attacker in a guest virtual machine could use this to cause a denial of service (system crash) in the KVM host. (CVE-2016-8630) Eyal Itkin discovered that the IP over IEEE 1394 (FireWire) implementation in the Linux kernel contained a buffer overflow when handling fragmented packets. A remote attacker could use this to possibly execute arbitrary code with administrative privileges. (CVE-2016-8633) Marco Grassi discovered that the TCP implementation in the Linux kernel mishandles socket buffer (skb) truncation. A local attacker could use this to cause a denial of service (system crash). (CVE-2016-8645) It was discovered that the keyring implementation in the Linux kernel improperly handled crypto registration in conjunction with successful key- type registration. A local attacker could use this to cause a denial of service (system crash). (CVE-2016-9313) Andrey Konovalov discovered that the SCTP implementation in the Linux kernel improperly handled validation of incoming data. A remote attacker could use this to cause a denial of service (system crash). (CVE-2016-9555)

Affected SoftwareAffected VersionHow to fix
All of
ubuntu/linux-image-4.8.0-32-generic<4.8.0-32.34
4.8.0-32.34
=16.10
All of
ubuntu/linux-image-powerpc-e500mc<4.8.0.32.41
4.8.0.32.41
=16.10
All of
ubuntu/linux-image-4.8.0-32-powerpc-smp<4.8.0-32.34
4.8.0-32.34
=16.10
All of
ubuntu/linux-image-4.8.0-32-powerpc-e500mc<4.8.0-32.34
4.8.0-32.34
=16.10
All of
ubuntu/linux-image-powerpc-smp<4.8.0.32.41
4.8.0.32.41
=16.10
All of
ubuntu/linux-image-generic<4.8.0.32.41
4.8.0.32.41
=16.10
All of
ubuntu/linux-image-4.8.0-32-generic-lpae<4.8.0-32.34
4.8.0-32.34
=16.10
All of
ubuntu/linux-image-lowlatency<4.8.0.32.41
4.8.0.32.41
=16.10
All of
ubuntu/linux-image-powerpc64-emb<4.8.0.32.41
4.8.0.32.41
=16.10
All of
ubuntu/linux-image-generic-lpae<4.8.0.32.41
4.8.0.32.41
=16.10
All of
ubuntu/linux-image-4.8.0-32-powerpc64-emb<4.8.0-32.34
4.8.0-32.34
=16.10
All of
ubuntu/linux-image-4.8.0-32-lowlatency<4.8.0-32.34
4.8.0-32.34
=16.10

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Child vulnerabilities

(Contains the following vulnerabilities)

Frequently Asked Questions

  • What is the severity of USN-3162-1?

    The severity of USN-3162-1 is not specified in the information provided.

  • How do I fix USN-3162-1?

    To fix USN-3162-1, update the affected software to the specified version.

  • Which software versions are affected by USN-3162-1?

    The affected software versions for USN-3162-1 are 16.10 with Linux kernel versions 4.8.0-32.34 and 4.8.0.32.41.

  • What is the impact of USN-3162-1?

    USN-3162-1 can cause a denial of service (system crash) if exploited by a local attacker.

  • Where can I find more information about USN-3162-1?

    More information about USN-3162-1 can be found at the links provided: https://ubuntu.com/security/CVE-2016-9313, https://ubuntu.com/security/CVE-2016-6213, https://ubuntu.com/security/CVE-2016-8630.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203