UBUNTU-CVE-2016-8632
Dashboard / Vulnerabilities / UBUNTU-CVE-2016-8632
UBUNTU-CVE-2016-8632
Summary:
Details: The tipc_msg_build function in net/tipc/msg.c in the Linux kernel through 4.8.11 does not validate the relationship between the minimum fragment length and the maximum packet size, which allows local users to gain privileges or cause a denial of service (heap-based buffer overflow) by leveraging the CAP_NET_ADMIN capability.
References: https://ubuntu.com/security/CVE-2016-8632, https://www.mail-archive.com/[email protected]/msg133205.html, https://ubuntu.com/security/notices/USN-3190-1, https://ubuntu.com/security/notices/USN-3190-2, https://ubuntu.com/security/notices/USN-3312-1, https://ubuntu.com/security/notices/USN-3312-2, https://ubuntu.com/security/notices/USN-3470-1, https://ubuntu.com/security/notices/USN-3470-2, https://www.cve.org/CVERecord?id=CVE-2016-8632
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
