UBUNTU-CVE-2016-2117
Dashboard / Vulnerabilities / UBUNTU-CVE-2016-2117
UBUNTU-CVE-2016-2117
Summary:
Details: The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c in the Linux kernel through 4.5.2 incorrectly enables scatter/gather I/O, which allows remote attackers to obtain sensitive information from kernel memory by reading packet data.
References: https://ubuntu.com/security/CVE-2016-2117, http://www.openwall.com/lists/oss-security/2016/03/16/7, https://ubuntu.com/security/notices/USN-2989-1, https://ubuntu.com/security/notices/USN-2998-1, https://ubuntu.com/security/notices/USN-3000-1, https://ubuntu.com/security/notices/USN-3001-1, https://ubuntu.com/security/notices/USN-3002-1, https://ubuntu.com/security/notices/USN-3003-1, https://ubuntu.com/security/notices/USN-3004-1, https://ubuntu.com/security/notices/USN-3005-1, https://ubuntu.com/security/notices/USN-3006-1, https://ubuntu.com/security/notices/USN-3007-1, https://www.cve.org/CVERecord?id=CVE-2016-2117
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
