ALT-BU-2017-2919-1
Branch p7 update bulletin.
Package kernel-image-un-def updated to version 4.1.38-alt0.M70P.1 for branch p7 in task 177539.
Closed vulnerabilities
BDU:2016-02353
Уязвимость компонента net/packet/af_packet.c ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании или повысить свои привилегии
Modified: 2025-04-12
CVE-2016-10088
The sg implementation in the Linux kernel through 4.9 does not properly restrict write operations in situations where the KERNEL_DS option is set, which allows local users to read or write to arbitrary kernel memory locations or cause a denial of service (use-after-free) by leveraging access to a /dev/sg device, related to block/bsg.c and drivers/scsi/sg.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-9576.
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=128394eff343fc6d2f32172f03e24829539c5835
- http://rhn.redhat.com/errata/RHSA-2017-0817.html
- http://www.openwall.com/lists/oss-security/2016/12/30/1
- http://www.securityfocus.com/bid/95169
- http://www.securitytracker.com/id/1037538
- https://access.redhat.com/errata/RHSA-2017:1842
- https://access.redhat.com/errata/RHSA-2017:2077
- https://access.redhat.com/errata/RHSA-2017:2669
- https://github.com/torvalds/linux/commit/128394eff343fc6d2f32172f03e24829539c5835
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=128394eff343fc6d2f32172f03e24829539c5835
- http://rhn.redhat.com/errata/RHSA-2017-0817.html
- http://www.openwall.com/lists/oss-security/2016/12/30/1
- http://www.securityfocus.com/bid/95169
- http://www.securitytracker.com/id/1037538
- https://access.redhat.com/errata/RHSA-2017:1842
- https://access.redhat.com/errata/RHSA-2017:2077
- https://access.redhat.com/errata/RHSA-2017:2669
- https://github.com/torvalds/linux/commit/128394eff343fc6d2f32172f03e24829539c5835
Modified: 2025-04-12
CVE-2016-7039
The IP stack in the Linux kernel through 4.8.2 allows remote attackers to cause a denial of service (stack consumption and panic) or possibly have unspecified other impact by triggering use of the GRO path for large crafted packets, as demonstrated by packets that contain only VLAN headers, a related issue to CVE-2016-8666.
- http://rhn.redhat.com/errata/RHSA-2016-2047.html
- http://rhn.redhat.com/errata/RHSA-2016-2107.html
- http://rhn.redhat.com/errata/RHSA-2016-2110.html
- http://www.openwall.com/lists/oss-security/2016/10/10/15
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html
- http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html
- http://www.securityfocus.com/bid/93476
- https://access.redhat.com/errata/RHSA-2017:0372
- https://bto.bluecoat.com/security-advisory/sa134
- https://bugzilla.redhat.com/show_bug.cgi?id=1375944
- https://patchwork.ozlabs.org/patch/680412/
- http://rhn.redhat.com/errata/RHSA-2016-2047.html
- http://rhn.redhat.com/errata/RHSA-2016-2107.html
- http://rhn.redhat.com/errata/RHSA-2016-2110.html
- http://www.openwall.com/lists/oss-security/2016/10/10/15
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html
- http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html
- http://www.securityfocus.com/bid/93476
- https://access.redhat.com/errata/RHSA-2017:0372
- https://bto.bluecoat.com/security-advisory/sa134
- https://bugzilla.redhat.com/show_bug.cgi?id=1375944
- https://patchwork.ozlabs.org/patch/680412/
Modified: 2025-04-12
CVE-2016-7425
The arcmsr_iop_message_xfer function in drivers/scsi/arcmsr/arcmsr_hba.c in the Linux kernel through 4.8.2 does not restrict a certain length field, which allows local users to gain privileges or cause a denial of service (heap-based buffer overflow) via an ARCMSR_MESSAGE_WRITE_WQBUFFER control code.
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=7bc2b55a5c030685b399bb65b6baa9ccc3d1f167
- http://marc.info/?l=linux-scsi&m=147394713328707&w=2
- http://marc.info/?l=linux-scsi&m=147394796228991&w=2
- http://www.openwall.com/lists/oss-security/2016/09/17/2
- http://www.securityfocus.com/bid/93037
- http://www.ubuntu.com/usn/USN-3144-1
- http://www.ubuntu.com/usn/USN-3144-2
- http://www.ubuntu.com/usn/USN-3145-1
- http://www.ubuntu.com/usn/USN-3145-2
- http://www.ubuntu.com/usn/USN-3146-1
- http://www.ubuntu.com/usn/USN-3146-2
- http://www.ubuntu.com/usn/USN-3147-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1377330
- https://github.com/torvalds/linux/commit/7bc2b55a5c030685b399bb65b6baa9ccc3d1f167
- https://security-tracker.debian.org/tracker/CVE-2016-7425
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=7bc2b55a5c030685b399bb65b6baa9ccc3d1f167
- http://marc.info/?l=linux-scsi&m=147394713328707&w=2
- http://marc.info/?l=linux-scsi&m=147394796228991&w=2
- http://www.openwall.com/lists/oss-security/2016/09/17/2
- http://www.securityfocus.com/bid/93037
- http://www.ubuntu.com/usn/USN-3144-1
- http://www.ubuntu.com/usn/USN-3144-2
- http://www.ubuntu.com/usn/USN-3145-1
- http://www.ubuntu.com/usn/USN-3145-2
- http://www.ubuntu.com/usn/USN-3146-1
- http://www.ubuntu.com/usn/USN-3146-2
- http://www.ubuntu.com/usn/USN-3147-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1377330
- https://github.com/torvalds/linux/commit/7bc2b55a5c030685b399bb65b6baa9ccc3d1f167
- https://security-tracker.debian.org/tracker/CVE-2016-7425
Modified: 2025-04-12
CVE-2016-8632
The tipc_msg_build function in net/tipc/msg.c in the Linux kernel through 4.8.11 does not validate the relationship between the minimum fragment length and the maximum packet size, which allows local users to gain privileges or cause a denial of service (heap-based buffer overflow) by leveraging the CAP_NET_ADMIN capability.
- http://www.openwall.com/lists/oss-security/2016/11/08/5
- http://www.securityfocus.com/bid/94211
- https://bugzilla.redhat.com/show_bug.cgi?id=1390832
- https://www.mail-archive.com/netdev%40vger.kernel.org/msg133205.html
- http://www.openwall.com/lists/oss-security/2016/11/08/5
- http://www.securityfocus.com/bid/94211
- https://bugzilla.redhat.com/show_bug.cgi?id=1390832
- https://www.mail-archive.com/netdev%40vger.kernel.org/msg133205.html
Modified: 2025-04-12
CVE-2016-8655
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket version, related to the packet_set_ring and packet_setsockopt functions.
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=84ac7260236a49c79eede91617700174c2c19b0c
- http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00044.html
- http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00054.html
- http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00055.html
- http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00056.html
- http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00067.html
- http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00070.html
- http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00073.html
- http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00076.html
- http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00077.html
- http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00087.html
- http://packetstormsecurity.com/files/140063/Linux-Kernel-4.4.0-AF_PACKET-Race-Condition-Privilege-Escalation.html
- http://rhn.redhat.com/errata/RHSA-2017-0386.html
- http://rhn.redhat.com/errata/RHSA-2017-0387.html
- http://rhn.redhat.com/errata/RHSA-2017-0402.html
- http://www.openwall.com/lists/oss-security/2016/12/06/1
- http://www.securityfocus.com/bid/94692
- http://www.securitytracker.com/id/1037403
- http://www.securitytracker.com/id/1037968
- http://www.ubuntu.com/usn/USN-3149-1
- http://www.ubuntu.com/usn/USN-3149-2
- http://www.ubuntu.com/usn/USN-3150-1
- http://www.ubuntu.com/usn/USN-3150-2
- http://www.ubuntu.com/usn/USN-3151-1
- http://www.ubuntu.com/usn/USN-3151-2
- http://www.ubuntu.com/usn/USN-3151-3
- http://www.ubuntu.com/usn/USN-3151-4
- http://www.ubuntu.com/usn/USN-3152-1
- http://www.ubuntu.com/usn/USN-3152-2
- https://bugzilla.redhat.com/show_bug.cgi?id=1400019
- https://github.com/torvalds/linux/commit/84ac7260236a49c79eede91617700174c2c19b0c
- https://source.android.com/security/bulletin/2017-03-01.html
- https://www.exploit-db.com/exploits/40871/
- https://www.exploit-db.com/exploits/44696/
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=84ac7260236a49c79eede91617700174c2c19b0c
- http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00044.html
- http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00054.html
- http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00055.html
- http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00056.html
- http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00067.html
- http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00070.html
- http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00073.html
- http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00076.html
- http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00077.html
- http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00087.html
- http://packetstormsecurity.com/files/140063/Linux-Kernel-4.4.0-AF_PACKET-Race-Condition-Privilege-Escalation.html
- http://rhn.redhat.com/errata/RHSA-2017-0386.html
- http://rhn.redhat.com/errata/RHSA-2017-0387.html
- http://rhn.redhat.com/errata/RHSA-2017-0402.html
- http://www.openwall.com/lists/oss-security/2016/12/06/1
- http://www.securityfocus.com/bid/94692
- http://www.securitytracker.com/id/1037403
- http://www.securitytracker.com/id/1037968
- http://www.ubuntu.com/usn/USN-3149-1
- http://www.ubuntu.com/usn/USN-3149-2
- http://www.ubuntu.com/usn/USN-3150-1
- http://www.ubuntu.com/usn/USN-3150-2
- http://www.ubuntu.com/usn/USN-3151-1
- http://www.ubuntu.com/usn/USN-3151-2
- http://www.ubuntu.com/usn/USN-3151-3
- http://www.ubuntu.com/usn/USN-3151-4
- http://www.ubuntu.com/usn/USN-3152-1
- http://www.ubuntu.com/usn/USN-3152-2
- https://bugzilla.redhat.com/show_bug.cgi?id=1400019
- https://github.com/torvalds/linux/commit/84ac7260236a49c79eede91617700174c2c19b0c
- https://source.android.com/security/bulletin/2017-03-01.html
- https://www.exploit-db.com/exploits/40871/
- https://www.exploit-db.com/exploits/44696/
Modified: 2025-04-12
CVE-2016-8666
The IP stack in the Linux kernel before 4.6 allows remote attackers to cause a denial of service (stack consumption and panic) or possibly have unspecified other impact by triggering use of the GRO path for packets with tunnel stacking, as demonstrated by interleaved IPv4 headers and GRE headers, a related issue to CVE-2016-7039.
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=fac8e0f579695a3ecbc4d3cac369139d7f819971
- http://rhn.redhat.com/errata/RHSA-2016-2047.html
- http://rhn.redhat.com/errata/RHSA-2016-2107.html
- http://rhn.redhat.com/errata/RHSA-2016-2110.html
- http://rhn.redhat.com/errata/RHSA-2017-0004.html
- http://www.openwall.com/lists/oss-security/2016/10/13/11
- http://www.securityfocus.com/bid/93562
- https://access.redhat.com/errata/RHSA-2017:0372
- https://bto.bluecoat.com/security-advisory/sa134
- https://bugzilla.redhat.com/show_bug.cgi?id=1384991
- https://bugzilla.suse.com/show_bug.cgi?id=1001486
- https://github.com/torvalds/linux/commit/fac8e0f579695a3ecbc4d3cac369139d7f819971
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=fac8e0f579695a3ecbc4d3cac369139d7f819971
- http://rhn.redhat.com/errata/RHSA-2016-2047.html
- http://rhn.redhat.com/errata/RHSA-2016-2107.html
- http://rhn.redhat.com/errata/RHSA-2016-2110.html
- http://rhn.redhat.com/errata/RHSA-2017-0004.html
- http://www.openwall.com/lists/oss-security/2016/10/13/11
- http://www.securityfocus.com/bid/93562
- https://access.redhat.com/errata/RHSA-2017:0372
- https://bto.bluecoat.com/security-advisory/sa134
- https://bugzilla.redhat.com/show_bug.cgi?id=1384991
- https://bugzilla.suse.com/show_bug.cgi?id=1001486
- https://github.com/torvalds/linux/commit/fac8e0f579695a3ecbc4d3cac369139d7f819971