Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.871768
Category:Red Hat Local Security Checks
Title:RedHat Update for kernel RHSA-2017:0386-01
Summary:The remote host is missing an update for the 'kernel'; package(s) announced via the referenced advisory.
Description:Summary:
The remote host is missing an update for the 'kernel'
package(s) announced via the referenced advisory.

Vulnerability Insight:
The kernel packages contain the Linux
kernel, the core of any Linux operating system.

Security Fix(es):

* Linux kernel built with the Kernel-based Virtual Machine (CONFIG_KVM)
support is vulnerable to a null pointer dereference flaw. It could occur on
x86 platform, when emulating an undefined instruction. An attacker could
use this flaw to crash the host kernel resulting in DoS. (CVE-2016-8630,
Important)

* A race condition issue leading to a use-after-free flaw was found in the
way the raw packet sockets implementation in the Linux kernel networking
subsystem handled synchronization while creating the TPACKET_V3 ring
buffer. A local user able to open a raw packet socket (requires the
CAP_NET_RAW capability) could use this flaw to elevate their privileges on
the system. (CVE-2016-8655, Important)

* A flaw was discovered in the Linux kernel's implementation of VFIO. An
attacker issuing an ioctl can create a situation where memory is corrupted
and modify memory outside of the expected area. This may overwrite kernel
memory and subvert kernel execution. (CVE-2016-9083, Important)

* The use of a kzalloc with an integer multiplication allowed an integer
overflow condition to be reached in vfio_pci_intrs.c. This combined with
CVE-2016-9083 may allow an attacker to craft an attack and use unallocated
memory, potentially crashing the machine. (CVE-2016-9084, Moderate)

Red Hat would like to thank Philip Pettersson for reporting CVE-2016-8655.

Additional Changes:

Space precludes documenting all of the bug fixes and enhancements included
in this advisory. To see the complete list of bug fixes and enhancements,
refer to the linked KnowledgeBase article.

Affected Software/OS:
kernel on
Red Hat Enterprise Linux Server (v. 7)

Solution:
Please Install the Updated Packages.

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-8630
94459
http://www.securityfocus.com/bid/94459
RHSA-2017:0386
http://rhn.redhat.com/errata/RHSA-2017-0386.html
RHSA-2017:0387
http://rhn.redhat.com/errata/RHSA-2017-0387.html
[oss-security] 20161122 CVE-2016-8630 kernel: kvm: x86: NULL pointer dereference duringinstruction decode
http://www.openwall.com/lists/oss-security/2016/11/22/3
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=d9092f52d7e61dd1557f2db2400ddb430e85937e
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.8.7
https://bugzilla.redhat.com/show_bug.cgi?id=1393350
https://github.com/torvalds/linux/commit/d9092f52d7e61dd1557f2db2400ddb430e85937e
Common Vulnerability Exposure (CVE) ID: CVE-2016-8655
1037403
http://www.securitytracker.com/id/1037403
1037968
http://www.securitytracker.com/id/1037968
40871
https://www.exploit-db.com/exploits/40871/
44696
https://www.exploit-db.com/exploits/44696/
94692
http://www.securityfocus.com/bid/94692
RHSA-2017:0402
http://rhn.redhat.com/errata/RHSA-2017-0402.html
SUSE-SU-2016:3096
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00044.html
SUSE-SU-2016:3113
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00054.html
SUSE-SU-2016:3116
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00055.html
SUSE-SU-2016:3117
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00056.html
SUSE-SU-2016:3169
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00067.html
SUSE-SU-2016:3183
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00070.html
SUSE-SU-2016:3197
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00073.html
SUSE-SU-2016:3205
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00076.html
SUSE-SU-2016:3206
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00077.html
SUSE-SU-2016:3247
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00087.html
USN-3149-1
http://www.ubuntu.com/usn/USN-3149-1
USN-3149-2
http://www.ubuntu.com/usn/USN-3149-2
USN-3150-1
http://www.ubuntu.com/usn/USN-3150-1
USN-3150-2
http://www.ubuntu.com/usn/USN-3150-2
USN-3151-1
http://www.ubuntu.com/usn/USN-3151-1
USN-3151-2
http://www.ubuntu.com/usn/USN-3151-2
USN-3151-3
http://www.ubuntu.com/usn/USN-3151-3
USN-3151-4
http://www.ubuntu.com/usn/USN-3151-4
USN-3152-1
http://www.ubuntu.com/usn/USN-3152-1
USN-3152-2
http://www.ubuntu.com/usn/USN-3152-2
[oss-security] 20161206 CVE-2016-8655 Linux af_packet.c race condition (local root)
http://www.openwall.com/lists/oss-security/2016/12/06/1
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=84ac7260236a49c79eede91617700174c2c19b0c
http://packetstormsecurity.com/files/140063/Linux-Kernel-4.4.0-AF_PACKET-Race-Condition-Privilege-Escalation.html
https://bugzilla.redhat.com/show_bug.cgi?id=1400019
https://github.com/torvalds/linux/commit/84ac7260236a49c79eede91617700174c2c19b0c
https://source.android.com/security/bulletin/2017-03-01.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-9083
BugTraq ID: 93929
http://www.securityfocus.com/bid/93929
http://www.openwall.com/lists/oss-security/2016/10/26/11
RedHat Security Advisories: RHSA-2017:0386
RedHat Security Advisories: RHSA-2017:0387
Common Vulnerability Exposure (CVE) ID: CVE-2016-9084
BugTraq ID: 93930
http://www.securityfocus.com/bid/93930
CopyrightCopyright (C) 2017 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.