Vulnerability Description
The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c in the Linux kernel through 4.5.2 incorrectly enables scatter/gather I/O, which allows remote attackers to obtain sensitive information from kernel memory by reading packet data.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Vm Server | 3.3 |
| Canonical | Ubuntu Linux | 12.04 |
| Linux | Linux Kernel | <= 4.5.2 |
Related Weaknesses (CWE)
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f43bfaVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2574.html
- http://rhn.redhat.com/errata/RHSA-2016-2584.html
- http://www.debian.org/security/2016/dsa-3607
- http://www.openwall.com/lists/oss-security/2016/03/16/7
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.h
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htm
- http://www.securityfocus.com/bid/84500
- http://www.ubuntu.com/usn/USN-2989-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2998-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-3000-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-3001-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-3002-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-3003-1
- http://www.ubuntu.com/usn/USN-3004-1Third Party Advisory
FAQ
What is CVE-2016-2117?
CVE-2016-2117 is a vulnerability with a CVSS score of 7.5 (HIGH). The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c in the Linux kernel through 4.5.2 incorrectly enables scatter/gather I/O, which allows remote attackers to obtain sensitive informat...
How severe is CVE-2016-2117?
CVE-2016-2117 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-2117?
Check the references section above for vendor advisories and patch information. Affected products include: Oracle Vm Server, Canonical Ubuntu Linux, Linux Linux Kernel.