Linux kernel IPT_SO_SET_REPLACE DoS Vulnerability (CVE-2016-4997)
Linux kernel IPT_SO_SET_REPLACE DoS Vulnerability (CVE-2016-4997)
Release date:
Updated on:
Affected Systems:
Linux kernel <4.6.3
Description:
CVE (CAN) ID: CVE-2016-4997
Linux Kernel is the Kernel of the Linux operating system.
In versions earlier than Linux kernel 4.6.3, The compat IPT_SO_SET_REPLACE setsockopt implementation in the netfilter subsystem has a security vulnerability. Local users can exploit this vulnerability to escalate permissions or cause DoS attacks.
<* Source: Wade Mealing
*>
Suggestion:
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit? Id = ce683e5f9d045e5d67d1312a42b359cb2ab2a13c
Https://github.com/torvalds/linux/commit/ce683e5f9d045e5d67d1312a42b359cb2ab2a13c
Http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.6.3
Https://bugzilla.redhat.com/show_bug.cgi? Id = 1349722
This article permanently updates the link address: