Heap-based buffer overflow in Linux kernel - CVE-2016-5829

 

Heap-based buffer overflow in Linux kernel - CVE-2016-5829

Published: October 1, 2016 / Updated: April 16, 2018


Vulnerability identifier: #VU4080
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5829
CWE-ID: CWE-122
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to cause DoS condition or gain elevated privileges on the target system.

The weakness exists in the hiddev_ioctl_usage function in drivers/hid/usbhid/hiddev.c  due to heap-based buffer overflow. A local attacker can cause the service to crash or gain elevated privileges via a crafted (1) HIDIOCGUSAGES or (2) HIDIOCSUSAGES ioctl call.

Affected software

Linux kernel
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
SUSE Linux
Fedora

kernel (Red Hat package)
kernel

How to mitigate CVE-2016-5829

Update to version 4.6.3.

kernel (Red Hat package) - update to 2.6.32-642.6.1.el6
kernel - addressed in versions 4.5.7-202.fc23, 4.6.4-301.fc24

External References

Related Security Bulletins