Memory corruption in Oracle VM Server for x86 and Oracle Linux - CVE-2016-4998

 

Memory corruption in Oracle VM Server for x86 and Oracle Linux - CVE-2016-4998

Published: June 27, 2016 / Updated: November 22, 2018


Vulnerability identifier: #VU28
CSH Severity: Medium
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-4998
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause denial of service conditions on the target system.

The vulnerability exists due to memory access error. A local user can cause the target sysetm to crash by issuing a specially crafted IPT_SO_SET_REPLACE setsockopt() call.

Successful exploitation of this vulnerability may result in the crash of the target sysetm.

Affected software

Oracle VM Server for x86
Oracle Linux
SUSE Linux
Fedora
kernel

How to mitigate CVE-2016-4998

The vendor has issued a fix (3.14.73, 4.4.14, 4.6.3).

kernel - addressed in versions 4.4.14-200.fc22, 4.5.7-202.fc23, 4.6.3-300.fc24

External References

Related Security Bulletins