Man-in-the-middle attack in Linux kernel - CVE-2016-5696

 

Man-in-the-middle attack in Linux kernel - CVE-2016-5696

Published: September 7, 2016 / Updated: April 7, 2020


Vulnerability identifier: #VU357
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5696
CWE-ID: CWE-300
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to write arbitrary files and cause DoS condition on the target system.

The weakness exists due to an error in net/ipv4/tcp_input.c while determining the rate of challenge ACK segments. A remote attacker can perform man-in-the-middle attack and hijack TCP sessions via a blind in-window attack.


Affected software

Linux kernel
Arch Linux
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Fedora

MRG Realtime
kernel (Red Hat package)
kernel-rt (Red Hat package)
kernel
IBM Storwize V3700
IBM Storwize V3500
IBM Storwize V5000
IBM Storwize V7000
IBM FlashSystem V9000

How to mitigate CVE-2016-5696

Update to version 4.7.

kernel (Red Hat package) - addressed in versions 2.6.32-431.73.2.el6, 2.6.32-504.52.1.el6, 2.6.32-573.34.1.el6, 2.6.32-642.4.2.el6, 3.10.0-229.40.1.el7, 3.10.0-327.28.3.el7
kernel-rt (Red Hat package) - addressed in versions 3.10.0-327.rt56.195.el6rt, 3.10.0-327.28.3.rt56.235.el7
kernel - addressed in versions 4.6.4-201.fc23, 4.6.4-301.fc24
IBM Storwize V3700 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V3500 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V5000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V7000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM FlashSystem V9000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins