ZeroHour

CVE-2016-3134

CVSS 3.0
8.4 high
EPSS
1%p67
Published
()
Modified
Description

The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.

Vendors
novelllinux
Products
suse linux enterprise software development kit, suse linux enterprise debuginfo, suse linux enterprise desktop, suse linux enterprise live patching, suse linux enterprise module for public cloud, suse linux enterprise real time extension, suse linux enterprise server, suse linux enterprise workstation extension, linux kernel
Weakness
CWE-119
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.