CVE-2016-2085

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The evm_verify_hmac function in security/integrity/evm/evm_main.c in the Linux kernel before 4.5 does not properly copy data, which makes it easier for local users to forge MAC values via a timing side-channel attack.

References

http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=613317bd212c585c20796c10afe5daaa95d4b0a1

http://www.ubuntu.com/usn/USN-2946-1

http://www.ubuntu.com/usn/USN-2946-2

http://www.ubuntu.com/usn/USN-2947-1

http://www.ubuntu.com/usn/USN-2947-2

http://www.ubuntu.com/usn/USN-2947-3

http://www.ubuntu.com/usn/USN-2948-1

http://www.ubuntu.com/usn/USN-2948-2

http://www.ubuntu.com/usn/USN-2949-1

https://bugzilla.redhat.com/show_bug.cgi?id=1324867

https://github.com/torvalds/linux/commit/613317bd212c585c20796c10afe5daaa95d4b0a1

https://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-2085.html

https://security-tracker.debian.org/tracker/CVE-2016-2085

Details

Source: MITRE

Published: 2016-04-27

Updated: 2016-12-03

Type: CWE-19

Risk Information

CVSS v2

Base Score: 2.1

Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Impact Score: 2.9

Exploitability Score: 3.9

Severity: LOW

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Impact Score: 3.6

Exploitability Score: 1.8

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions up to 4.4.8 (inclusive)

Tenable Plugins

View all (12 total)

IDNameProductFamilySeverity
133913EulerOS 2.0 SP5 : kernel (EulerOS-SA-2020-1112)NessusHuawei Local Security Checks
critical
124981EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1528)NessusHuawei Local Security Checks
high
93679OracleVM 3.4 : Unbreakable / etc (OVMSA-2016-0100)NessusOracleVM Local Security Checks
critical
93148Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2016-3596)NessusOracle Linux Local Security Checks
critical
90507Ubuntu 14.04 LTS : linux-lts-utopic regression (USN-2948-2)NessusUbuntu Local Security Checks
critical
90406Ubuntu 14.04 LTS : linux-lts-vivid vulnerabilities (USN-2949-1)NessusUbuntu Local Security Checks
critical
90405Ubuntu 14.04 LTS : linux-lts-utopic vulnerabilities (USN-2948-1)NessusUbuntu Local Security Checks
critical
90404Ubuntu 15.10 : linux-raspi2 vulnerabilities (USN-2947-3)NessusUbuntu Local Security Checks
critical
90403Ubuntu 14.04 LTS : linux-lts-wily vulnerabilities (USN-2947-2)NessusUbuntu Local Security Checks
critical
90402Ubuntu 15.10 : linux vulnerabilities (USN-2947-1)NessusUbuntu Local Security Checks
critical
90401Ubuntu 12.04 LTS : linux-lts-trusty vulnerabilities (USN-2946-2)NessusUbuntu Local Security Checks
critical
90400Ubuntu 14.04 LTS : linux vulnerabilities (USN-2946-1)NessusUbuntu Local Security Checks
critical