CVE-2016-4997

Advisory lineage Upstream: 0 Downstream: 44
Modified
Published: 03 Jul 2016, 21:00
Last modified:06 Aug 2024, 00:46

Vulnerability Summary

Overall Risk (default)
medium
42/100
CVSS Score
7.8 HIGH
v3.1 (nvd)
EPSS Score
5.49% LOW
5% probability -0.87%
KEV
Not listed
Ransomware
No reports
Public exploits
5 found
Dark Web
Not detected

Timeline

03 Jul 2016, 21:00
Published
Vulnerability first disclosed
06 Aug 2024, 00:46
Last Modified
Vulnerability information updated

Description

The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corruption) by leveraging in-container root access to provide a crafted offset value that triggers an unintended decrement.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 5.49% Percentile: 90%

Techniques & Countermeasures

  • CWE-264Permissions, Privileges, and Access Controls

    Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.

Affected Systems

  • canonicalubuntu_linux

    12.04 | 14.04 | 15.10 | 16.04

  • debiandebian_linux

    8.0

  • linuxlinux_kernel

    ≥ 2.6.17, < 3.2.80 | ≥ 3.3, < 3.10.103 | ≥ 3.11, < 3.12.62 | ≥ 3.13, < 3.14.73 | ≥ 3.15, < 3.16.37 | ≥ 3.17, < 3.18.37 | ≥ 3.19, < 4.1.28 | ≥ 4.2, < 4.4.14 | ≥ 4.5, < 4.6.3

  • novellsuse_linux_enterprise_desktop

    12.0 | 12.0:sp1

  • novellsuse_linux_enterprise_live_patching

    12.0

  • novellsuse_linux_enterprise_module_for_public_cloud

    12.0

  • novellsuse_linux_enterprise_real_time_extension

    12.0:sp1

  • novellsuse_linux_enterprise_server

    12.0 | 12.0:sp1

  • novellsuse_linux_enterprise_software_development_kit

    12.0 | 12.0:sp1

  • novellsuse_linux_enterprise_workstation_extension

    12.0 | 12.0:sp1

  • oraclelinux

    7

References (43)