USN-3206-1: Linux kernel vulnerabilities
It was discovered that a use-after-free vulnerability existed in the block device layer of the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly gain administrative privileges. (CVE-2016-7910) Dmitry Vyukov discovered a use-after-free vulnerability in the sysioprioget() function in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly gain administrative privileges. (CVE-2016-7911) Andrey Konovalov discovered a use-after-free vulnerability in the DCCP implementation in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly gain administrative privileges. (CVE-2017-6074)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Linux kernel vulnerability?
The vulnerability ID for this Linux kernel vulnerability is CVE-2016-7910.
What is the severity of CVE-2016-7910?
The severity of CVE-2016-7910 is high.
How does CVE-2016-7910 impact the Linux kernel?
CVE-2016-7910 can be exploited by a local attacker to cause a denial of service or possibly gain administrative privileges.
Which versions of Ubuntu are affected by CVE-2016-7910?
Ubuntu version 12.04 with the Linux kernel versions 3.2.0-1501.128, 3.2.0.123.138, 3.2.0-123.166, 3.2.0-123.166, 3.2.0-123.166, 3.2.0-123.166, 3.2.0.1501.96, 3.2.0-123.166, 3.2.0.123.138, 3.2.0.123.138, 3.2.0.123.138, 3.2.0-123.166, 3.2.0.123.138, 3.2.0.123.138, 3.2.0-123.166, 3.2.0.123.138, 3.2.0.123.138, 3.2.0.123.138, 3.2.0.123.138, 3.2.0.123.138 are affected by CVE-2016-7910.
How can I mitigate the CVE-2016-7910 vulnerability on Ubuntu 12.04?
To mitigate the CVE-2016-7910 vulnerability on Ubuntu 12.04, update the Linux kernel to version 3.2.0-1501.128 or later.