|
|
Subscribe / Log in / New account

Mageia alert MGASA-2016-0347 (kernel)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2016-0347: Updated kernel packages fixes security vulnerabilities
Date:  Thu, 20 Oct 2016 21:31:48 +0200
Message-ID:  <20161020193148.5F1F29F79F@duvel.mageia.org>

MGASA-2016-0347 - Updated kernel packages fixes security vulnerabilities Publication date: 20 Oct 2016 URL: http://advisories.mageia.org/MGASA-2016-0347.html Type: security Affected Mageia releases: 5 CVE: CVE-2016-5195, CVE-2016-6828, CVE-2016-7039 Description: This update is based on the upstream 4.4.26 kernel and fixes atleast theese security issues: A race condition was found in the way the Linux kernel's memory subsystem handled the copy-on-write (COW) breakage of private read-only memory mappings. An unprivileged local user could use this flaw to gain write access to otherwise read-only memory mappings and thus increase their privileges on the system. This could be abused by an attacker to modify existing setuid files with instructions to elevate privileges. An exploit using this technique has been found in the wild (CVE-2016-5195). Marco Grassi discovered a use-after-free condition could occur in the TCP retransmit queue handling code in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2016-6828) Vladimir Bene discovered an unbounded recursion in the VLAN and TEB Generic Receive Offload (GRO) processing implementations in the Linux kernel, A remote attacker could use this to cause a stack corruption, leading to a denial of service (system crash). (CVE-2016-7039) For other fixes in this update, see the referenced changelogs. References: - https://bugs.mageia.org/show_bug.cgi?id=19577 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.... - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.... - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.... - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.... - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5195 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6828 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7039 SRPMS: - 5/core/kernel-4.4.26-1.mga5 - 5/core/kernel-userspace-headers-4.4.26-1.mga5 - 5/core/kmod-vboxadditions-5.1.2-8.mga5 - 5/core/kmod-virtualbox-5.1.2-8.mga5 - 5/core/kmod-xtables-addons-2.10-14.mga5


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds