|
|
Log in / Subscribe / Register

kernel: two vulnerabilities

Package(s):kernel CVE #(s):CVE-2016-7097 CVE-2016-8666
Created:November 10, 2016 Updated:January 31, 2017
Description: From the Mageia advisory:

The filesystem implementation in the Linux kernel through 4.8.2 preserves the setgid bit during a setxattr call, which allows local users to gain group privileges by leveraging the existence of a setgid program with restrictions on execute permissions (CVE-2016-7097).

The IP stack in the Linux kernel before 4.6 allows remote attackers to cause a denial of service (stack consumption and panic) or possibly have unspecified other impact by triggering use of the GRO path for packets with tunnel stacking, as demonstrated by interleaved IPv4 headers and GRE headers, a related issue to CVE-2016-7039 (CVE-2016-8666).

Alerts:
Mageia MGASA-2016-0372 kernel 2016-11-10
SUSE SUSE-SU-2017:0494-1 the Linux Kernel 2017-02-17
SUSE SUSE-SU-2017:0471-1 kernel 2017-02-15
SUSE SUSE-SU-2017:0333-1 kernel 2017-01-30
SUSE SUSE-SU-2017:0181-1 kernel 2017-01-17
Oracle ELSA-2017-3508 kernel 4.1.12 2017-01-12
Oracle ELSA-2017-3508 kernel 4.1.12 2017-01-12
Red Hat RHSA-2017:0004-01 kernel 2017-01-03
SUSE SUSE-SU-2016:3304-1 kernel 2016-12-30
Debian-LTS DLA-772-1 kernel 2017-01-01
Ubuntu USN-3161-4 linux-snapdragon 2016-12-20
Ubuntu USN-3161-3 linux-raspi2 2016-12-20
Ubuntu USN-3162-2 linux-raspi2 2016-12-20
openSUSE openSUSE-SU-2016:3050-1 kernel 2016-12-08
openSUSE openSUSE-SU-2016:3058-1 kernel 2016-12-08
openSUSE openSUSE-SU-2016:3021-1 kernel 2016-12-06
SUSE SUSE-SU-2016:2976-1 the Linux Kernel 2016-12-02
Ubuntu USN-3146-2 linux-lts-xenial 2016-11-30
Ubuntu USN-3146-1 kernel 2016-11-30
Ubuntu USN-3147-1 kernel 2016-11-30
SUSE SUSE-SU-2016:2912-1 kernel 2016-11-25

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds