MGASA-2016-0401

Advisory lineage Upstream: 3 Downstream: 0
Published: 26 Nov 2016, 10:41
Last modified:16 Apr 2026, 06:22

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Nov 2016, 10:41
Published
Vulnerability first disclosed
16 Apr 2026, 06:22
Last Modified
Vulnerability information updated

Description

Updated kernel-4.4.32 packages fixes security vulnerabilities This update is based on upstream 4.4.32 and fixes at least the following security issues: The proc_keys_show function in security/keys/proc.c in the Linux kernel through 4.8.2, when the GNU Compiler Collection (gcc) stack protector is enabled, uses an incorrect buffer size for certain timeout data, which allows local users to cause a denial of service (stack memory corruption and panic) by reading the /proc/keys file (CVE-2016-7042). Null pointer dereference in kvm/emulate.c (CVE-2016-8630). A buffer overflow vulnerability due to a lack of input filtering of incoming fragmented datagrams was found in the IP-over-1394 driver [firewire-net] in a fragment handling code in the Linux kernel. A maliciously formed fragment with a respectively large datagram offset would cause a memcpy() past the datagram buffer, which would cause a system panic or possible arbitrary code execution. The flaw requires [firewire-net] module to be loaded and is remotely exploitable from connected firewire devices, but not over a local network (CVE-2016-8633). For other fixes in this update, see the referenced changelogs.

Affected Systems

  • mageiakernel

    < 4.4.32-1.mga5

  • mageiakernel-userspace-headers

    < 4.4.32-1.mga5

  • mageiakmod-vboxadditions

    < 5.1.2-11.mga5

  • mageiakmod-virtualbox

    < 5.1.2-11.mga5

  • mageiakmod-xtables-addons

    < 2.10-16.mga5

References (4)