|
|
Log in / Subscribe / Register

kernel: multiple vulnerabilities

Package(s):kernel CVE #(s):CVE-2015-8812 CVE-2016-2383 CVE-2016-2384 CVE-2016-0617
Created:February 29, 2016 Updated:March 15, 2016
Description: From the Red Hat bugzilla:

A flaw was found in the CXGB3 kernel driver when the network was considered congested. The kernel would incorrectly misinterpret the congestion as an error condition and incorrectly free/clean up the skb. When the device would then send the skb's queued, these structures would be referenced and may panic the system or allow an attacker to escalate privileges in a use-after-free scenario. (CVE-2015-8812)

When ctx access is used, the kernel often needs to expand/rewrite instructions, so after that patching, branch offsets have to be adjusted for both forward and backward jumps in the new eBPF program, but for backward jumps it fails to account the delta. Meaning, for example, if the expansion happens exactly on the insn that sits at the jump target, it doesn't fix up the back jump offset. (CVE-2016-2383)

A vulnerability was found in the Linux kernel. There is a possibility of double-free on 'umidi' object. The 'umidi' object will be free'd on the error path by snd_usbmidi_free() when tearing down the rawmidi interface causing the system panic. (CVE-2016-2384)

A flaw was found in the Linux kernel's hugetlbfs handling of punching holes in hugetlbfs files with either truncate or fallocate. When truncating a hugetlbfs file, this bug could prevent some pages from being unmapped. If pages are not properly unmapped during truncate, the kernel bug is hit which leads the system to panic. In the fallocate hole punch case, this bug could prevent pages from being unmapped as in the truncate case also. However, for hole punch the result is that unmapped pages will not be removed during the operation. For hole punch, it is also possible that more pages than desired will be unmapped. This unnecessary unmapping will cause page faults to reestablish the mappings on subsequent page access. (CVE-2016-0617)

Alerts:
Oracle ELSA-2016-2574 kernel 2016-11-10
Red Hat RHSA-2016:2584-02 kernel-rt 2016-11-03
Red Hat RHSA-2016:2574-02 kernel 2016-11-03
openSUSE openSUSE-SU-2016:2649-1 kernel 2016-10-26
openSUSE openSUSE-SU-2016:2144-1 kernel 2016-08-24
SUSE SUSE-SU-2016:2074-1 kernel 2016-08-15
SUSE SUSE-SU-2016:1764-1 kernel 2016-07-08
Ubuntu USN-2967-2 linux-ti-omap4 2016-05-09
Ubuntu USN-2967-1 kernel 2016-05-09
SUSE SUSE-SU-2016:1203-1 kernel 2016-05-03
SUSE SUSE-SU-2016:1102-1 kernel 2016-04-19
SUSE SUSE-SU-2016:1019-1 kernel 2016-04-12
Scientific Linux SLSA-2016:2574-2 kernel 2016-12-14
Ubuntu USN-2948-2 linux-lts-utopic 2016-04-11
openSUSE openSUSE-SU-2016:1008-1 kernel 2016-04-12
Ubuntu USN-2947-3 linux-raspi2 2016-04-06
Ubuntu USN-2947-2 linux-lts-wily 2016-04-06
Ubuntu USN-2949-1 linux-lts-vivid 2016-04-06
Ubuntu USN-2948-1 linux-lts-utopic 2016-04-06
Ubuntu USN-2946-2 linux-lts-trusty 2016-04-06
Ubuntu USN-2946-1 kernel 2016-04-06
Ubuntu USN-2947-1 kernel 2016-04-06
SUSE SUSE-SU-2016:0911-1 kernel 2016-03-30
Ubuntu USN-2930-3 linux-raspi2 2016-03-16
SUSE SUSE-SU-2016:0785-1 kernel 2016-03-16
Ubuntu USN-2928-2 linux-ti-omap4 2016-03-14
Ubuntu USN-2930-2 linux-lts-wily 2016-03-14
Ubuntu USN-2932-1 linux-lts-vivid 2016-03-14
Ubuntu USN-2931-1 linux-lts-utopic 2016-03-14
Ubuntu USN-2929-2 linux-lts-trusty 2016-03-14
Ubuntu USN-2928-1 kernel 2016-03-14
Ubuntu USN-2929-1 kernel 2016-03-14
Ubuntu USN-2930-1 kernel 2016-03-14
Fedora FEDORA-2016-9fbe2c258b kernel 2016-03-05
Debian DSA-3503-1 kernel 2016-03-03
Debian-LTS DLA-439-1 linux-2.6 2016-02-29
Fedora FEDORA-2016-e7162262b0 kernel 2016-02-28
Fedora FEDORA-2016-7e12ae5359 kernel 2016-02-28

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds