Out-of-bounds read in Linux kernel and linux_kernel (Debian package) - CVE-2016-10208

 

Out-of-bounds read in Linux kernel and linux_kernel (Debian package) - CVE-2016-10208

Published: May 23, 2017 / Updated: May 30, 2017


Vulnerability identifier: #VU6644
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-10208
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to cause DoS condition on the target systsem.

The weakness exists due to memory corruption when validating meta block groups by the ext4_fill_super function. A local attacker can use a specially crafted EXT4 image to trigger an out-of-bounds read and cause the system to crash.

Successful exploitation of the vulnerability results in denial of service.

Affected software

Linux kernel
CentOS
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for Real Time
SUSE Linux
linux_kernel (Debian package)
kernel (Red Hat package)
kernel-rt (Red Hat package)

MRG Realtime

How to mitigate CVE-2016-10208

Update to version 4.9.9.

kernel (Red Hat package) - update to 3.10.0-514.21.1.el7
kernel-rt (Red Hat package) - addressed in versions 3.10.0-514.rt56.221.el6rt, 3.10.0-514.21.1.rt56.438.el7

External References

Related Security Bulletins