Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2016-8399 |
CWE-ID | CWE-121 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software Subscribe |
Red Hat Enterprise Linux for Power, big endian - Extended Update Support Operating systems & Components / Operating system Red Hat Enterprise Linux for IBM z Systems - Extended Update Support Operating systems & Components / Operating system Red Hat Enterprise Linux Server - Extended Update Support Operating systems & Components / Operating system Red Hat Enterprise Linux EUS Compute Node Operating systems & Components / Operating system kernel (Red Hat package) Operating systems & Components / Operating system package or component |
Vendor |
Red Hat Inc. |
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU1255
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2016-8399
CWE-ID:
CWE-121 - Stack-based buffer overflow
Exploit availability: No
DescriptionThe vulnerability allows a local user to cause kernel panic or escalate privileges.
The vulnerability exists due to a boundary error when crating an ICMP header. A local user can create a very short ICMP header and execute arbitrary code within the contest of the kernel.
Successful exploitation of the vulnerability may allow a local user to escalate privileges on the system.
MitigationInstall updates from vendor's website.
Red Hat Enterprise Linux for Power, big endian - Extended Update Support: 6.7
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 6.7
Red Hat Enterprise Linux Server - Extended Update Support: 6.7
kernel (Red Hat package): 2.6.32-71.7.1.el6 - 2.6.32-573.40.1.el6
Red Hat Enterprise Linux EUS Compute Node: 6.7
:
http://access.redhat.com/errata/RHSA-2017:0869
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?