CVE-2016-3135

CVSS v3.1 7.8 (High)
78% Progress
CVSS v2.0 7.2 (High)
72% Progress
EPSS 0.04 % (5th)
0.04% Progress
Affected Products 2
Advisories 11

Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32-bit platforms allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.

Weaknesses
CWE-189
Numeric Errors
CWE-NVD-Other
CVE Status
PUBLISHED
CNA
OpenText
Published Date
2016-04-27 17:59:23
(8 years ago)
Updated Date
2023-11-07 02:32:09
(10 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel from 4.2 version and prior 4.4.21 version cpe:2.3:o:linux:linux_kernel >= 4.2 < 4.4.21
  Linux Kernel from 4.5 version and prior 4.6 version cpe:2.3:o:linux:linux_kernel >= 4.5 < 4.6

Configuration #2

    CPE23 From Up To
  Canonical Ubuntu Linux 14.04 cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts
  Canonical Ubuntu Linux 15.10 cpe:2.3:o:canonical:ubuntu_linux:15.10
  Canonical Ubuntu Linux 16.04 cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...