UBUNTU-CVE-2016-3135
Dashboard / Vulnerabilities / UBUNTU-CVE-2016-3135
UBUNTU-CVE-2016-3135
Summary:
Details: Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32-bit platforms allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.
References: https://ubuntu.com/security/CVE-2016-3135, https://code.google.com/p/google-security-research/issues/detail?id=758, http://marc.info/?l=netfilter-devel&m=145757136822750&w=2, http://www.openwall.com/lists/oss-security/2016/03/14/1, https://ubuntu.com/security/notices/USN-2930-1, https://ubuntu.com/security/notices/USN-2930-2, https://ubuntu.com/security/notices/USN-2930-3, https://ubuntu.com/security/notices/USN-3054-1, https://ubuntu.com/security/notices/USN-3055-1, https://ubuntu.com/security/notices/USN-3056-1, https://ubuntu.com/security/notices/USN-3057-1, https://www.cve.org/CVERecord?id=CVE-2016-3135
Affected packages
Package
Name: linux-lts-wily
Purl: pkg:deb/ubuntu/[email protected]~14.04.1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
