CWE
119
Advisory Published

USN-3162-2: Linux kernel (Raspberry Pi 2) vulnerabilities

First published: Tue Dec 20 2016(Updated: )

CAI Qian discovered that shared bind mounts in a mount namespace exponentially added entries without restriction to the Linux kernel's mount table. A local attacker could use this to cause a denial of service (system crash). (CVE-2016-6213) Andreas Gruenbacher and Jan Kara discovered that the filesystem implementation in the Linux kernel did not clear the setgid bit during a setxattr call. A local attacker could use this to possibly elevate group privileges. (CVE-2016-7097) Marco Grassi discovered that the driver for Areca RAID Controllers in the Linux kernel did not properly validate control messages. A local attacker could use this to cause a denial of service (system crash) or possibly gain privileges. (CVE-2016-7425) It was discovered that the KVM implementation for x86/x86_64 in the Linux kernel could dereference a null pointer. An attacker in a guest virtual machine could use this to cause a denial of service (system crash) in the KVM host. (CVE-2016-8630) Eyal Itkin discovered that the IP over IEEE 1394 (FireWire) implementation in the Linux kernel contained a buffer overflow when handling fragmented packets. A remote attacker could use this to possibly execute arbitrary code with administrative privileges. (CVE-2016-8633) Marco Grassi discovered that the TCP implementation in the Linux kernel mishandles socket buffer (skb) truncation. A local attacker could use this to cause a denial of service (system crash). (CVE-2016-8645) It was discovered that the keyring implementation in the Linux kernel improperly handled crypto registration in conjunction with successful key- type registration. A local attacker could use this to cause a denial of service (system crash). (CVE-2016-9313) Andrey Konovalov discovered that the SCTP implementation in the Linux kernel improperly handled validation of incoming data. A remote attacker could use this to cause a denial of service (system crash). (CVE-2016-9555)

Affected SoftwareAffected VersionHow to fix
All of
ubuntu/linux-image-4.8.0-1021-raspi2<4.8.0-1021.24
4.8.0-1021.24
=16.10
All of
ubuntu/linux-image-raspi2<4.8.0.1021.24
4.8.0.1021.24
=16.10

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Reference Links

Frequently Asked Questions

  • What is the vulnerability ID of this security advisory?

    The vulnerability ID of this security advisory is USN-3162-2.

  • What is the severity of the CVE-2016-6213 vulnerability?

    The severity of the CVE-2016-6213 vulnerability is not specified in the security advisory.

  • How can a local attacker exploit CVE-2016-6213?

    A local attacker can exploit CVE-2016-6213 by using shared bind mounts in a mount namespace to cause a denial of service (system crash).

  • Which versions of Ubuntu are affected by this vulnerability?

    Ubuntu Ubuntu 16.10 is affected by this vulnerability.

  • How can I fix the CVE-2016-6213 vulnerability?

    To fix the CVE-2016-6213 vulnerability, update your system to version 4.8.0-1021.24 of the Linux kernel.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203