CVE-2016-8399

HIGH

Description

An elevation of privilege vulnerability in the kernel networking subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process and current compiler optimizations restrict access to the vulnerable code. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31349935.

References

http://rhn.redhat.com/errata/RHSA-2017-0817.html

http://www.securityfocus.com/bid/94708

https://access.redhat.com/errata/RHSA-2017:0869

https://access.redhat.com/errata/RHSA-2017:2930

https://access.redhat.com/errata/RHSA-2017:2931

https://source.android.com/security/bulletin/2016-12-01.html

https://support.f5.com/csp/article/K23030550?utm_source=f5support&utm_medium=RSS

Details

Source: MITRE

Published: 2017-01-12

Updated: 2018-01-05

Type: CWE-284

Risk Information

CVSS v2.0

Base Score: 7.6

Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 4.9

Severity: HIGH

CVSS v3.0

Base Score: 7

Vector: CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1

Severity: HIGH

Tenable Plugins

View all (44 total)

IDNameProductFamilySeverity
127425NewStart CGSL MAIN 4.05 : kernel Multiple Vulnerabilities (NS-SA-2019-0152)NessusNewStart CGSL Local Security Checks
high
127146NewStart CGSL MAIN 5.04 : kernel Multiple Vulnerabilities (NS-SA-2019-0004)NessusNewStart CGSL Local Security Checks
critical
124992EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1539)NessusHuawei Local Security Checks
critical
124819EulerOS Virtualization 3.0.1.0 : kernel (EulerOS-SA-2019-1496)NessusHuawei Local Security Checks
critical
104132Virtuozzo 7 : readykernel-patch (VZA-2017-098)NessusVirtuozzo Local Security Checks
high
104131Virtuozzo 7 : readykernel-patch (VZA-2017-097)NessusVirtuozzo Local Security Checks
high
104107F5 Networks BIG-IP : Linux kernel vulnerability (K23030550)NessusF5 Networks Local Security Checks
high
104106CentOS 7 : kernel (CESA-2017:2930)NessusCentOS Local Security Checks
high
104088Oracle Linux 7 : kernel (ELSA-2017-2930-1) (BlueBorne)NessusOracle Linux Local Security Checks
critical
104008Scientific Linux Security Update : kernel on SL7.x x86_64 (20171019)NessusScientific Linux Local Security Checks
high
104004RHEL 7 : kernel-rt (RHSA-2017:2931)NessusRed Hat Local Security Checks
high
104003RHEL 7 : kernel (RHSA-2017:2930)NessusRed Hat Local Security Checks
high
104001Oracle Linux 7 : kernel (ELSA-2017-2930)NessusOracle Linux Local Security Checks
high
102774OracleVM 3.4 : Unbreakable / etc (OVMSA-2017-0145) (Stack Clash)NessusOracleVM Local Security Checks
critical
102773Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2017-3609) (Stack Clash)NessusOracle Linux Local Security Checks
critical
100238OracleVM 3.2 : Unbreakable / etc (OVMSA-2017-0106)NessusOracleVM Local Security Checks
critical
100237OracleVM 3.3 : Unbreakable / etc (OVMSA-2017-0105)NessusOracleVM Local Security Checks
critical
100235Oracle Linux 6 : Unbreakable Enterprise kernel (ELSA-2017-3567)NessusOracle Linux Local Security Checks
critical
100234Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2017-3566)NessusOracle Linux Local Security Checks
critical
99337RHEL 6 : kernel (RHSA-2017:0869)NessusRed Hat Local Security Checks
high
99218Scientific Linux Security Update : kernel on SL6.x i386/x86_64 (20170321)NessusScientific Linux Local Security Checks
high
99164OracleVM 3.2 : Unbreakable / etc (OVMSA-2017-0058)NessusOracleVM Local Security Checks
high
99163OracleVM 3.3 : Unbreakable / etc (OVMSA-2017-0057) (Dirty COW)NessusOracleVM Local Security Checks
critical
99162OracleVM 3.4 : Unbreakable / etc (OVMSA-2017-0056)NessusOracleVM Local Security Checks
high
99161Oracle Linux 6 : Unbreakable Enterprise kernel (ELSA-2017-3535)NessusOracle Linux Local Security Checks
high
99160Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2017-3534)NessusOracle Linux Local Security Checks
high
99159Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2017-3533)NessusOracle Linux Local Security Checks
high
99106Virtuozzo 6 : parallels-server-bm-release / vzkernel / etc (VZA-2017-025)NessusVirtuozzo Local Security Checks
critical
99074Oracle Linux 6 : kernel (ELSA-2017-0817)NessusOracle Linux Local Security Checks
high
97962CentOS 6 : kernel (CESA-2017:0817)NessusCentOS Local Security Checks
high
97886RHEL 6 : kernel (RHSA-2017:0817)NessusRed Hat Local Security Checks
high
97297SUSE SLES11 Security Update : kernel (SUSE-SU-2017:0494-1)NessusSuSE Local Security Checks
critical
97205SUSE SLES12 Security Update : kernel (SUSE-SU-2017:0471-1)NessusSuSE Local Security Checks
high
97189SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2017:0464-1)NessusSuSE Local Security Checks
high
97098Ubuntu 16.10 : linux-raspi2 vulnerabilities (USN-3190-2)NessusUbuntu Local Security Checks
critical
97097SUSE SLES11 Security Update : kernel (SUSE-SU-2017:0437-1)NessusSuSE Local Security Checks
critical
97018Ubuntu 16.10 : linux vulnerabilities (USN-3190-1)NessusUbuntu Local Security Checks
critical
97017Ubuntu 14.04 LTS : linux-lts-xenial vulnerabilities (USN-3189-2)NessusUbuntu Local Security Checks
high
97016Ubuntu 16.04 LTS : linux, linux-raspi2, linux-snapdragon vulnerabilities (USN-3189-1)NessusUbuntu Local Security Checks
high
96903SUSE SLES11 Security Update : kernel (SUSE-SU-2017:0333-1)NessusSuSE Local Security Checks
critical
96284Amazon Linux AMI : kernel (ALAS-2017-782)NessusAmazon Linux Local Security Checks
high
96188Debian DLA-772-1 : linux security updateNessusDebian Local Security Checks
critical
96027Fedora 24 : kernel (2016-e5b72816d0)NessusFedora Local Security Checks
high
96019Fedora 25 : kernel (2016-02db2f32fd)NessusFedora Local Security Checks
high