#VU456 Integer overflow


Published: 2016-09-15 | Updated: 2018-05-01

Vulnerability identifier: #VU456

Vulnerability risk: Low

CVSSv3.1:

CVE-ID: CVE-2016-0758

CWE-ID: CWE-190

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description
The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists in lib/asn1_decoder.c due to integer overflow. A local attacker can submit specially crafted ASN.1 data and gain root privileges.

Mitigation
Update to version 4.6.

Vulnerable software versions

Linux kernel: 4.5.0 - 4.5.7


CPE

External links
http://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=23c8a812dc3c621009e4f0...


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?


Latest bulletins with this vulnerability