The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message.
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00044.html
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.html
http://www.debian.org/security/2016/dsa-3607
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.5
http://www.openwall.com/lists/oss-security/2016/05/04/26
http://www.securityfocus.com/bid/90015
http://www.ubuntu.com/usn/USN-2989-1
http://www.ubuntu.com/usn/USN-2996-1
http://www.ubuntu.com/usn/USN-2997-1
http://www.ubuntu.com/usn/USN-2998-1
http://www.ubuntu.com/usn/USN-3000-1
http://www.ubuntu.com/usn/USN-3001-1
http://www.ubuntu.com/usn/USN-3002-1
http://www.ubuntu.com/usn/USN-3003-1
http://www.ubuntu.com/usn/USN-3004-1
http://www.ubuntu.com/usn/USN-3005-1
http://www.ubuntu.com/usn/USN-3006-1
http://www.ubuntu.com/usn/USN-3007-1
https://bugzilla.redhat.com/show_bug.cgi?id=1333309
https://github.com/torvalds/linux/commit/b8670c09f37bdf2847cc44f36511a53afc6161fd
Source: MITRE
Published: 2016-05-23
Updated: 2016-11-28
Type: CWE-200
Base Score: 5
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
Impact Score: 2.9
Exploitability Score: 10
Severity: MEDIUM
Base Score: 7.5
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Impact Score: 3.6
Exploitability Score: 3.9
Severity: HIGH
OR
cpe:2.3:o:novell:suse_linux_enterprise_debuginfo:11:sp4:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux_enterprise_server:11:extra:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux_enterprise_server:11:sp4:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux_enterprise_software_development_kit:11.0:sp4:*:*:*:*:*:*
OR
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
OR
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions up to 4.5.4 (inclusive)
ID | Name | Product | Family | Severity |
---|---|---|---|---|
124973 | EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1520) | Nessus | Huawei Local Security Checks | high |
100238 | OracleVM 3.2 : Unbreakable / etc (OVMSA-2017-0106) | Nessus | OracleVM Local Security Checks | critical |
100235 | Oracle Linux 6 : Unbreakable Enterprise kernel (ELSA-2017-3567) | Nessus | Oracle Linux Local Security Checks | critical |
99163 | OracleVM 3.3 : Unbreakable / etc (OVMSA-2017-0057) (Dirty COW) | Nessus | OracleVM Local Security Checks | critical |
99160 | Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2017-3534) | Nessus | Oracle Linux Local Security Checks | high |
97120 | OracleVM 3.2 : Unbreakable / etc (OVMSA-2017-0041) | Nessus | OracleVM Local Security Checks | medium |
97119 | OracleVM 3.3 : Unbreakable / etc (OVMSA-2017-0040) | Nessus | OracleVM Local Security Checks | medium |
97118 | Oracle Linux 6 : Unbreakable Enterprise kernel (ELSA-2017-3516) | Nessus | Oracle Linux Local Security Checks | medium |
97117 | Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2017-3515) | Nessus | Oracle Linux Local Security Checks | medium |
97079 | OracleVM 3.4 : Unbreakable / etc (OVMSA-2017-0039) | Nessus | OracleVM Local Security Checks | high |
97057 | Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2017-3514) | Nessus | Oracle Linux Local Security Checks | high |
96903 | SUSE SLES11 Security Update : kernel (SUSE-SU-2017:0333-1) | Nessus | SuSE Local Security Checks | critical |
93445 | openSUSE Security Update : the Linux Kernel (openSUSE-2016-1076) | Nessus | SuSE Local Security Checks | critical |
93370 | SUSE SLES11 Security Update : kernel (SUSE-SU-2016:2245-1) | Nessus | SuSE Local Security Checks | critical |
93164 | SUSE SLES11 Security Update : kernel (SUSE-SU-2016:1672-1) | Nessus | SuSE Local Security Checks | high |
93104 | openSUSE Security Update : the Linux Kernel (openSUSE-2016-1015) | Nessus | SuSE Local Security Checks | critical |
92195 | Fedora 24 : kernel (2016-ef973efab7) | Nessus | Fedora Local Security Checks | high |
92133 | Fedora 22 : kernel (2016-a159c484e4) | Nessus | Fedora Local Security Checks | medium |
92055 | Fedora 23 : kernel (2016-06f1572324) | Nessus | Fedora Local Security Checks | high |
91886 | Debian DSA-3607-1 : linux - security update | Nessus | Debian Local Security Checks | critical |
91736 | openSUSE Security Update : the Linux Kernel (openSUSE-2016-753) | Nessus | SuSE Local Security Checks | critical |
91687 | Debian DLA-516-1 : linux security update | Nessus | Debian Local Security Checks | critical |
91569 | Ubuntu 16.04 LTS : linux-raspi2 vulnerabilities (USN-3007-1) | Nessus | Ubuntu Local Security Checks | high |
91568 | Ubuntu 16.04 LTS : linux vulnerabilities (USN-3006-1) | Nessus | Ubuntu Local Security Checks | high |
91567 | Ubuntu 14.04 LTS : linux-lts-xenial vulnerabilities (USN-3005-1) | Nessus | Ubuntu Local Security Checks | high |
91566 | Ubuntu 15.10 : linux-raspi2 vulnerabilities (USN-3004-1) | Nessus | Ubuntu Local Security Checks | critical |
91565 | Ubuntu 15.10 : linux vulnerabilities (USN-3003-1) | Nessus | Ubuntu Local Security Checks | critical |
91564 | Ubuntu 14.04 LTS : linux-lts-wily vulnerabilities (USN-3002-1) | Nessus | Ubuntu Local Security Checks | critical |
91563 | Ubuntu 14.04 LTS : linux-lts-vivid vulnerabilities (USN-3001-1) | Nessus | Ubuntu Local Security Checks | critical |
91562 | Ubuntu 14.04 LTS : linux-lts-utopic vulnerabilities (USN-3000-1) | Nessus | Ubuntu Local Security Checks | critical |
91560 | Ubuntu 12.04 LTS : linux-lts-trusty vulnerabilities (USN-2998-1) | Nessus | Ubuntu Local Security Checks | critical |
91559 | Ubuntu 12.04 LTS : linux vulnerabilities (USN-2996-1) | Nessus | Ubuntu Local Security Checks | critical |
91425 | Ubuntu 14.04 LTS : linux vulnerabilities (USN-2989-1) | Nessus | Ubuntu Local Security Checks | critical |
91241 | Amazon Linux AMI : kernel (ALAS-2016-703) | Nessus | Amazon Linux Local Security Checks | high |