Integer overflow in Linux kernel - CVE-2016-0758

 

Integer overflow in Linux kernel - CVE-2016-0758

Published: September 15, 2016 / Updated: May 1, 2018


Vulnerability identifier: #VU456
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-0758
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists in lib/asn1_decoder.c due to integer overflow. A local attacker can submit specially crafted ASN.1 data and gain root privileges.

Affected software

Linux kernel
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Ubuntu

MRG Realtime
kernel-rt (Red Hat package)

How to mitigate CVE-2016-0758

Update to version 4.6.

kernel-rt (Red Hat package) - addressed in versions 3.10.0-327.rt56.183.el6rt, 3.10.0-327.18.2.rt56.223.el7_2

External References

Related Security Bulletins