vulnerability
SUSE: CVE-2016-8632: SUSE Linux Security Advisory
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
7 | (AV:L/AC:L/Au:N/C:C/I:C/A:C) | Nov 27, 2016 | Dec 9, 2016 | Feb 4, 2022 |
Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Nov 27, 2016
Added
Dec 9, 2016
Modified
Feb 4, 2022
Description
The tipc_msg_build function in net/tipc/msg.c in the Linux kernel through 4.8.11 does not validate the relationship between the minimum fragment length and the maximum packet size, which allows local users to gain privileges or cause a denial of service (heap-based buffer overflow) by leveraging the CAP_NET_ADMIN capability.
Solution(s)
suse-upgrade-cluster-md-kmp-defaultsuse-upgrade-cluster-network-kmp-defaultsuse-upgrade-dlm-kmp-defaultsuse-upgrade-gfs2-kmp-defaultsuse-upgrade-kernel-defaultsuse-upgrade-kernel-docssuse-upgrade-kernel-ec2suse-upgrade-kernel-ec2-develsuse-upgrade-kernel-ec2-extrasuse-upgrade-kernel-obs-buildsuse-upgrade-ocfs2-kmp-default
References
- SUSE-SUSE-SU-2016:3039-1
- SUSE-SUSE-SU-2016:3049-1
- SUSE-SUSE-SU-2016:3063-1
- SUSE-SUSE-SU-2017:0226-1
- SUSE-SUSE-SU-2017:0227-1
- SUSE-SUSE-SU-2017:0228-1
- SUSE-SUSE-SU-2017:0229-1
- SUSE-SUSE-SU-2017:0230-1
- SUSE-SUSE-SU-2017:0231-1
- SUSE-SUSE-SU-2017:0233-1
- SUSE-SUSE-SU-2017:0234-1
- SUSE-SUSE-SU-2017:0235-1
- SUSE-SUSE-SU-2017:0244-1
- SUSE-SUSE-SU-2017:0245-1
- SUSE-SUSE-SU-2017:0246-1
- SUSE-SUSE-SU-2017:0247-1
- SUSE-SUSE-SU-2017:0248-1
- SUSE-SUSE-SU-2017:0249-1
- SUSE-SUSE-SU-2017:0268-1
- SUSE-SUSE-SU-2017:0278-1
- SUSE-SUSE-SU-2017:0333-1
- SUSE-SUSE-SU-2017:0407-1
- SUSE-SUSE-SU-2017:0437-1
- SUSE-SUSE-SU-2017:0494-1
- SUSE-SUSE-SU-2017:1102-1
- BID-94211
- NVD-CVE-2016-8632
- UBUNTU-USN-3190-1
- UBUNTU-USN-3190-2
- UBUNTU-USN-3312-1
- UBUNTU-USN-3312-2
- UBUNTU-USN-3470-1
- UBUNTU-USN-3470-2

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.