UBUNTU-CVE-2016-2383
Dashboard / Vulnerabilities / UBUNTU-CVE-2016-2383
UBUNTU-CVE-2016-2383
Summary:
Details: The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the backward-jump case, which allows local users to obtain sensitive information from kernel memory by creating a packet filter and then loading crafted BPF instructions.
References: https://ubuntu.com/security/CVE-2016-2383, http://www.openwall.com/lists/oss-security/2016/02/14/1, https://ubuntu.com/security/notices/USN-2947-1, https://ubuntu.com/security/notices/USN-2947-2, https://ubuntu.com/security/notices/USN-2947-3, https://www.cve.org/CVERecord?id=CVE-2016-2383
Affected packages
Package
Name: linux-lts-wily
Purl: pkg:deb/ubuntu/[email protected]~14.04.1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
