“Use-after-free” error in Linux kernel - CVE-2016-6828
Published: September 7, 2016 / Updated: May 30, 2020
Vulnerability identifier: #VU360
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6828
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows local users to provoke a denial of service.
The vulnerability predicts TCP realization by a local user.
Successful exploitation of this vulnerability will allow an attacker to cause a denial of service.
Affected software
Linux kernel
Amazon Linux AMI
Ubuntu
Fedora
kernel
Amazon Linux AMI
Ubuntu
Fedora
kernel
How to mitigate CVE-2016-6828
Install update from vendor's website.
Linux kernel - update to 4.1.37
kernel - addressed in versions 4.6.7-200.fc23, 4.6.7-300.fc24, 4.7.2-100.fc23, 4.7.2-101.fc23, 4.7.2-200.fc24, 4.7.2-201.fc24
kernel - addressed in versions 4.6.7-200.fc23, 4.6.7-300.fc24, 4.7.2-100.fc23, 4.7.2-101.fc23, 4.7.2-200.fc24, 4.7.2-201.fc24
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Ubuntu update for Linux kernel (OMAP4)
- Ubuntu update for Linux kernel (Trusty HWE)
- Ubuntu update for Linux kernel
- Ubuntu update for Linux kernel (Qualcomm Snapdragon)
- Ubuntu update for Linux kernel (Raspberry Pi 2)
- Ubuntu update for Linux kernel (Xenial HWE)
- Ubuntu update for Linux kernel
- Amazon Linux AMI update for kernel
- Fedora 23 update for kernel
- Fedora 24 update for kernel
- Fedora 24 update for kernel
- Fedora 23 update for kernel
- Fedora 24 update for kernel
- Fedora 23 update for kernel